Statement of Guidance

Annex VIII - Sector-Specific Guidance Notes for Digital Asset Business

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is Annex VIII to the Bermuda Monetary Authority's AML/ATF guidance notes, providing sector-specific guidance for persons conducting digital asset business (DAB), also known as virtual currency business, in or from Bermuda. It supplements (but does not replace) the main AML/ATF guidance notes and sets out how AML/ATF obligations under Bermuda's Acts and Regulations apply specifically to digital asset activities.

  • Who it covers: Persons designated as AML/ATF regulated financial institutions (RFIs) by virtue of conducting digital asset business as defined in Section 2(2) of the Digital Asset Business Act 2018, including issuing/selling/redeeming digital assets, payment service provision using digital assets, operating digital asset exchanges, providing custodial wallet services, and acting as a digital asset services vendor.
  • Senior management duties: Senior management must ensure compliance with AML/ATF Acts and Regulations, identify and mitigate ML/TF risks, conduct and maintain an AML and sanctions risk assessment, appoint a Compliance Officer and a Reporting Officer, screen employees, resource and deliver training, and audit and test AML/ATF controls.
  • Licensing link: Persons conducting DAB must obtain a BMA licence before commencing business (subject to exemptions under Section 11 of the DABA), and must submit AML/ATF policies and procedures with the licence application.
  • Group and cross-border requirements: DAB group structures must not obstruct effective consolidated supervision, and Bermuda RFIs with foreign agents, branches, subsidiaries or representative offices must communicate their AML/ATF policies to those entities and ensure equivalent AML/ATF standards are applied.
  • Customer due diligence and monitoring: Guidance addresses CDD tailored to digital asset business, including customer and beneficial owner identification, source of funds/wealth, timing of CDD, simplified and enhanced due diligence, agent network onboarding and oversight, wire transfer and money transmission requirements, sanctions screening, ongoing monitoring, and suspicious activity reporting.
  • Risk factor guidance: Sets out sector-specific customer, product/service, transaction, delivery channel, agent/third-party and geographic risk factors relevant to assessing ML/TF risk in digital asset business.

Failure to comply with the underlying Regulations is a criminal offence carrying fines up to $50,000 on summary conviction or up to $750,000 and/or two years' imprisonment on indictment; the BMA may also impose civil penalties of up to $10,000,000 per breach under the Supervision and Enforcement Act 2008. Departures from the guidance should be documented and justifiable to the BMA.

Key obligations

  • RFIs conducting digital asset business must obtain a BMA licence under Section 10 of the DABA before commencing business, unless an exemption under Section 11 applies.
  • Senior management must appoint a Compliance Officer at senior management level and a Reporting Officer to process client disclosures.
  • Senior management must conduct and keep up to date an AML and Sanctions risk assessment covering customers, products, services, transactions, delivery channels, outsourcing arrangements and geographic connections.
  • RFIs must establish and maintain detailed risk-based AML/ATF policies, procedures and controls, and periodically audit and test them for effectiveness.
  • An RFI must include its AML/ATF policies and procedures with its digital asset business licence application under Section 12(6)(c) of the DABA.
  • A digital asset business must ensure its group structure does not obstruct effective consolidated supervision.
  • RFIs with agents, branches, subsidiaries or representative offices outside Bermuda must communicate their AML/ATF policies to those entities and ensure they apply AML/ATF measures at least equivalent to Bermuda's requirements.
  • RFIs must screen employees, provide adequate AML/ATF training, and address issues identified through audits and testing in a timely manner.
  • RFIs must apply customer due diligence, including enhanced due diligence where appropriate, and ongoing monitoring specific to digital asset business risks.
  • RFIs must comply with suspicious activity reporting obligations and be aware of failure-to-report and tipping-off offences.
  • RFIs must maintain records in accordance with the record-keeping requirements referenced in the guidance.

Applies to

digital asset business (DAB) providers / virtual currency businesses, AML/ATF regulated financial institutions (RFIs) conducting digital asset business, digital asset exchanges, digital asset custodial wallet service providers, payment service providers utilising digital assets, digital asset services vendors, agents and third parties of digital asset businesses

Topics

Version history

2026-07-07

source file (current)