Statement of Guidance

AML/ATF Sectoral Guidance Notes for CSPs (2021) - Annex VI

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is Annex VI to the BMA's 2021 AML/ATF Guidance Notes, providing sector-specific guidance for corporate service provider (CSP) business. It supplements, but does not replace, the general Guidance Notes, and applies to persons carrying on CSP business who are designated as AML/ATF regulated financial institutions (RFIs) under Section 42A(1)(fa) of POCA.

  • Scope: Covers CSP business as defined in the Corporate Service Provider Business Act 2012, including company/partnership formation agency, nominee services, registered office and administrative/secretarial services, resident representative functions, and related additional services.
  • Senior management duties: Requires senior management to ensure compliance, approve AML/ATF policies, identify and mitigate ML/TF risks, appoint a Compliance Officer and Reporting Officer, screen employees, resource compliance functions, provide training, and independently audit and test controls.
  • Group and third-party oversight: Where a CSP RFI has overseas branches, subsidiaries or group members, it must communicate its AML/ATF policies to them and ensure they apply measures at least equivalent to Bermuda's requirements.
  • Screening obligations: Regulation 18(1)(c) requires screening of owners, directors, managers and employees against high standards, including where screening is outsourced to third parties.
  • Customer due diligence and monitoring: Sets out CSP-specific expectations for CDD, beneficial ownership identification and verification, source of wealth/funds, ongoing monitoring, sanctions screening, and suspicious activity reporting.
  • Licensing submissions: Under Section 10(2)(c) of the Corporate Service Provider Business Act 2012, an RFI must include its AML/ATF policies and procedures with its CSP business licence application, and should also submit business and client risk assessments at that time.
  • Penalties: Non-compliance with specified regulations is a criminal offence carrying fines up to $50,000 on summary conviction, or up to $750,000 and/or two years' imprisonment on indictment; the BMA may also impose civil penalties up to $10,000,000 per failure under Section 20 of the POCA SEA.

The annex also lists CSP-specific ML/TF risk indicators (customer, transaction, delivery channel and third-party risk factors) intended to inform risk-based CDD and enhanced due diligence decisions, and reiterates that non-compliance with this guidance may be taken into account by the BMA or the Supreme Court in enforcement determinations.

Key obligations

  • Senior management of RFIs conducting CSP business must ensure compliance with the acts and regulations and approve AML/ATF policies, procedures and controls.
  • RFIs must appoint a Compliance Officer at managerial level to oversee AML/ATF policies, procedures and controls.
  • RFIs must appoint a Reporting Officer to receive and process internal disclosures of suspicion.
  • RFIs must screen owners, directors, managers and employees against high standards under Regulation 18(1)(c), including verifying the effectiveness of any third-party screening relied upon.
  • RFIs must establish and maintain detailed AML/ATF policies, procedures and controls adequate to forestall and prevent ML/TF.
  • An RFI must include its AML/ATF policies and procedures with its application for a CSP business licence under Section 10(2)(c) of the Corporate Service Provider Business Act 2012, and should submit a business risk assessment and client risk assessment at the time of application.
  • Where an RFI conducting CSP business has overseas branches, subsidiaries, representative offices or group members, it must communicate its AML/ATF policies and procedures to them and ensure equivalent AML/ATF measures are applied.
  • RFIs must conduct customer due diligence, including identifying and verifying customers and beneficial owners, and apply enhanced due diligence where required.
  • RFIs must conduct ongoing monitoring of business relationships and transactions and file suspicious activity reports where required.
  • RFIs must maintain adequate records in accordance with record-keeping requirements referenced in the guidance.

Applies to

Corporate service providers (CSPs), AML/ATF regulated financial institutions (RFIs) conducting CSP business, Senior management, Compliance Officers and Reporting Officers of CSP RFIs

Topics

Version history

2026-07-07

source file (current)