Statement of Guidance

Annex VIII - Sector-Specific Guidance Notes for Digital Asset Business (DAB)

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This Annex VIII provides sector-specific AML/ATF guidance from the Bermuda Monetary Authority for entities conducting Digital Asset Business (DAB), also known as virtual currency business. It supplements (but does not replace) the BMA's main AML/ATF guidance notes, and explains how existing anti-money laundering and anti-terrorist financing obligations under Bermuda's Proceeds of Crime Act, Anti-Terrorism (Financial and Other Measures) Act, and related Regulations apply specifically to digital asset activities.

  • Scope: Applies to any person providing, as a business to the general public: issuing/selling/redeeming digital assets (including ICOs run for clients), payment services using digital assets, operating a digital asset exchange, providing custodial wallet services, or acting as a digital assets services vendor.
  • Governance: Senior management must ensure AML/ATF compliance, conduct and keep updated an AML/Sanctions risk assessment, appoint a Compliance Officer and a Reporting Officer, screen employees, and provide adequate training and resources.
  • Customer due diligence: Sets out DAB-specific approaches to identifying customers and beneficial owners, timing of CDD, source of funds/wealth checks, simplified and enhanced due diligence, and handling of one-off and linked transactions.
  • Agents and cross-border groups: RFIs with overseas agents, branches, subsidiaries or representative offices must communicate their AML/ATF policies to those entities and ensure they apply measures at least equivalent to Bermuda's requirements.
  • Ongoing obligations: Covers ongoing monitoring, international sanctions screening, suspicious activity reporting (including failure-to-report and tipping-off offences), record-keeping, and sector-specific ML/TF risk factors relating to customers, products, delivery channels, agents and geography.

The guidance carries evidentiary weight: courts and the Authority must consider whether an RFI followed this guidance when assessing breaches of AML/ATF law. Non-compliance with underlying Regulations remains a criminal offence (fines up to $750,000 and/or imprisonment) and the Authority may impose civil penalties of up to $10,000,000 per contravention under the SEA Act 2008.

Key obligations

  • Senior management must ensure compliance with the AML/ATF Acts and Regulations and identify, assess and mitigate ML/TF risks across customers, products, services, delivery channels, outsourcing and geography.
  • RFIs conducting DAB must conduct an AML and Sanctions risk assessment and keep the findings up to date.
  • RFIs must appoint a Compliance Officer at senior management level and a Reporting Officer to process disclosures.
  • RFIs must establish and maintain detailed risk-based AML/ATF policies, procedures and controls, and periodically audit and test them for effectiveness.
  • Persons conducting DAB must obtain a licence from the BMA prior to commencing business, and must include AML/ATF policies and procedures with the DAB licence application.
  • DAB groups must ensure their group structure does not obstruct effective consolidated supervision.
  • RFIs with overseas agents, branches, subsidiaries or representative offices must communicate their AML/ATF policies to those entities and ensure equivalent AML/ATF measures are applied.
  • RFIs must perform customer due diligence, including identification and beneficial ownership verification, appropriate to one-off transactions, occasional transactions and ongoing business relationships.
  • RFIs must apply enhanced due diligence for higher-risk digital asset business and simplified due diligence only where appropriate.
  • RFIs must conduct ongoing monitoring of business relationships and transactions, and screen for international sanctions.
  • RFIs must file suspicious activity reports and avoid tipping-off, and must train employees and agents on AML/ATF obligations.
  • RFIs must maintain records in accordance with record-keeping requirements.

Applies to

Digital asset business (DAB) providers, AML/ATF regulated financial institutions (RFIs) conducting digital asset business, Virtual currency exchanges, Digital asset custodial wallet service providers, Digital asset payment service providers, Digital asset services vendors, Agents and third parties of DAB entities

Topics

Version history

2026-07-07

source file (current)

2026-07-07

source file