Statement of Guidance

Guidance Notes for AML/ATF Regulated Financial Institutions 2022 - Annex VI: Sector-Specific Guidance Notes (SSGN) for Corporate Service Provider (CSP) Business

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is Annex VI of the BMA's 2022 AML/ATF Guidance Notes, providing sector-specific guidance for Corporate Service Provider (CSP) business in Bermuda. It applies to persons carrying on CSP business within the meaning of the Corporate Service Provider Business Act 2012, who are designated as AML/ATF Regulated Financial Institutions (RFIs) under the Proceeds of Crime Act 1997. The annex supplements, but does not replace, the general Guidance Notes, and sets out how core AML/ATF obligations (senior management responsibilities, customer due diligence, ongoing monitoring, suspicious activity reporting, record-keeping) apply specifically to CSP activities such as company formation, nominee services, registered office and administrative/secretarial services, and resident representative functions.

  • Governance: Senior management must ensure compliance with AML/ATF acts and regulations, approve AML/ATF policies and procedures, identify and mitigate ML/TF risks, and maintain documented, up-to-date risk assessments.
  • Officers: RFIs must appoint a suitably qualified compliance officer at managerial level and a reporting officer to receive and consider internal disclosures of suspicion.
  • Screening: Owners, directors, managers and employees of CSPs must be screened against high standards, including where screening is outsourced to third parties.
  • Licensing link: AML/ATF policies and procedures, along with business and client risk assessments, must be included with an application for a CSP business licence under the Corporate Service Provider Business Act 2012.
  • Group policies: Where a Bermuda CSP has overseas branches, subsidiaries or group members, it must communicate its AML/ATF policies to them and ensure equivalent AML/ATF measures are applied.
  • Customer due diligence: RFIs must identify and verify customers and beneficial owners in the CSP context, understand the nature and purpose of the business relationship, and apply enhanced due diligence for higher-risk CSP relationships.
  • Monitoring and reporting: RFIs must conduct ongoing monitoring of business relationships and transactions, and file suspicious activity reports where required, while avoiding tipping-off.
  • Records and training: RFIs must maintain records and ensure employees receive appropriate AML/ATF training and awareness.

The annex also lists CSP-specific ML/TF risk factors (e.g., unusual transactions, third-party and delivery-channel risks) that RFIs should consider when applying a risk-based approach, and notes the significant civil and criminal penalties (fines up to $50,000 on summary conviction, up to $750,000 and/or two years' imprisonment on indictment, or BMA penalties up to $10 million) for non-compliance with the underlying regulations.

Key obligations

  • Senior management must ensure compliance with applicable AML/ATF acts and regulations and approve the RFI's AML/ATF policies, procedures and controls.
  • RFIs conducting CSP business must appoint a compliance officer at managerial level to oversee AML/ATF policies, procedures and controls.
  • RFIs must appoint a reporting officer to receive and assess internal disclosures of suspicion of ML/TF and to determine whether to file suspicious activity reports.
  • RFIs must screen owners, directors, managers and employees against high standards, including satisfying themselves as to the adequacy of any third-party screening relied upon.
  • RFIs must include their AML/ATF policies and procedures, and should submit business and client risk assessments, with their CSP business licence application.
  • RFIs with overseas branches, subsidiaries or group members must communicate their AML/ATF policies and procedures to those entities and ensure equivalent AML/ATF measures are applied.
  • RFIs must conduct customer due diligence, including identifying and verifying customers and beneficial owners specific to the CSP business context.
  • RFIs must apply enhanced due diligence for higher-risk CSP customers and relationships.
  • RFIs must conduct ongoing monitoring of CSP business relationships and transactions.
  • RFIs must file suspicious activity reports where knowledge or suspicion of ML/TF arises and must avoid tipping-off.
  • RFIs must maintain adequate records of customer due diligence and transactions.
  • RFIs must provide appropriate AML/ATF training to relevant employees.

Applies to

Corporate Service Providers (CSPs), AML/ATF Regulated Financial Institutions (RFIs) conducting CSP business

Topics

Version history

2026-07-07

source file (current)