Statement of Guidance
Annex VI - Sector-Specific Guidance Notes for Corporate Service Provider Business
Status not confirmedView on BMA's website Source document
Summary
This is Annex VI of the Bermuda Monetary Authority's AML/ATF guidance notes, providing sector-specific guidance for persons carrying on corporate service provider (CSP) business, who are designated as AML/ATF regulated financial institutions (RFIs) under Bermuda's Proceeds of Crime Regulations. It supplements, but does not replace, the main AML/ATF guidance notes and explains how core obligations under Bermuda's AML/ATF Acts and Regulations apply specifically to CSP activities such as company formation, nominee services, registered office and administrative/secretarial services, and resident representative functions.
- Senior management and controls: Senior management must ensure compliance with the Acts and Regulations, identify and mitigate ML/TF risks, appoint a Compliance Officer and Reporting Officer, screen employees, resource AML/ATF controls adequately, and audit/test them periodically.
- Risk-based approach: RFIs must use a risk-based approach to set CDD levels, mitigation measures, monitoring scope and frequency, and suspicious activity detection, and must assess ML/TF risk when designing new products or services.
- Customer due diligence: Guidance covers identifying customers and beneficial owners in the CSP context, verifying identification information, timing of CDD, reliance on prior due diligence and third parties, and applying simplified or enhanced due diligence based on risk.
- Sanctions, monitoring and reporting: RFIs must screen against international sanctions, conduct on-going monitoring of business relationships, and have procedures for identifying and reporting suspicious activity while avoiding tipping-off offences.
- Training and record-keeping: RFIs must provide employee AML/ATF training and awareness and maintain records in line with the main guidance notes.
- Group and outsourcing requirements: Where a Bermuda RFI has branches, subsidiaries or representative offices abroad, it must communicate its AML/ATF policies to them and ensure they apply measures at least equivalent to Bermuda's, and must satisfy itself as to the effectiveness of any third-party screening or CDD reliance arrangements.
The annex also sets out numerous non-exhaustive risk factors (customer, product/service, transaction, delivery channel, third party and geographic) that CSP RFIs should consider when assessing ML/TF risk, and notes penalties for non-compliance, including criminal fines/imprisonment under the Regulations and civil penalties of up to $500,000 per contravention under the SEA Act 2008.
Key obligations
- RFIs conducting CSP business must appoint a Compliance Officer at senior management level and a Reporting Officer to process disclosures.
- RFIs must establish and maintain detailed AML/ATF policies, procedures and controls adequate to prevent ML/TF, and include these policies with any application for a CSP business licence.
- RFIs must apply a risk-based approach to determine CDD levels, risk-mitigation measures, monitoring scope/frequency, and suspicious activity detection and reporting measures.
- RFIs must screen owners, directors, managers and employees against high standards, including where screening is outsourced to a third party.
- RFIs with branches, subsidiaries or representative offices outside Bermuda must communicate their AML/ATF policies to those entities and ensure equivalent AML/ATF measures are applied.
- RFIs must assess the ML/TF risk of any new product or service before offering it.
- RFIs must screen customers and transactions against international sanctions.
- RFIs must conduct on-going monitoring of business relationships and have procedures for detecting and reporting suspicious activity, avoiding tipping-off.
- RFIs must provide employee AML/ATF training and awareness programmes.
- RFIs must maintain records in accordance with the main AML/ATF guidance notes.
- RFIs should document and be able to justify their risk assessments and any departures from the guidance.
Applies to
corporate service providers, AML/ATF regulated financial institutions (RFIs) conducting corporate service provider business