Regulation

Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008

Bermuda Monetary Authority (BMA) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-09-01)

Current version last checked: 2026-09-08

Summary

This is Bermuda's core AML/ATF regulation, made under the Proceeds of Crime Act 1997 and the Anti-Terrorism (Financial and Other Measures) Act 2004. It sets out detailed customer due diligence (CDD), record-keeping, internal control and wire-transfer requirements that regulated persons must follow to detect and prevent money laundering, terrorist financing and (as amended) proliferation financing. It has been amended numerous times since 2008, most recently by BR 70/2026 and BR 100/2025, to update definitions, beneficial ownership thresholds, PEP provisions and digital asset business coverage.

  • Who it applies to: AML/ATF regulated financial institutions, independent professionals (lawyers and accountants in certain transactions), casino operators, registered dealers in high value goods, real estate brokers and agents, and (for group-wide requirements) members of financial groups, all acting in the course of business carried on in or from Bermuda.
  • Customer due diligence: Requires identifying and verifying customers and beneficial owners, understanding ownership and control structures, identifying the relevant natural person acting as chief executive for legal entities, ongoing monitoring of business relationships, and specific timing rules for verification, including special rules for casinos and patron accounts.
  • Risk-based measures: Sets out when simplified due diligence may apply and when enhanced due diligence is mandatory, including for politically exposed persons (PEPs), and imposes extra controls for branches, subsidiaries, financial groups, shell banks, anonymous accounts, reliance on third parties and outsourcing.
  • Internal controls: Requires relevant persons to keep records, maintain systems and internal reporting procedures, provide an independent audit function, train staff, and appoint a Compliance Officer and Reporting Officer.
  • Wire transfers: Part 4 imposes obligations on payment service providers (payer, payee and intermediary) regarding information accompanying transfers of funds, handling missing or incomplete payer/payee information, batch transfers, and reporting when missing information makes a transaction suspicious.
  • Beneficial ownership tests: Defines beneficial owner for bodies corporate, partnerships, trusts, other legal arrangements and estates, generally using a 25% ownership/control threshold (reduced to 10% for corporate service providers).
  • Offences: Breach of specified requirements in Parts 3 and 4 constitutes an offence, reinforcing the compliance obligations imposed.

The Regulations do not set a single blanket compliance deadline; instead individual provisions and definitions have taken effect on various dates as amendments were made (e.g. 2015, 2017, 2018, 2020, 2021, 2022, 2025, 2026 amendments each with their own effective date noted in the text). Entities should check the amendment history for the version of a provision currently in force.

Key obligations

  • Relevant persons must apply customer due diligence measures, including identifying and verifying the customer's identity and, where applicable, the beneficial owner's identity, before or during establishment of a business relationship or occasional transaction.
  • Relevant persons must identify the natural person holding the position of chief executive (or equivalent) for legal entities and legal arrangements as part of CDD.
  • Relevant persons must conduct ongoing monitoring of business relationships.
  • Relevant persons must apply enhanced due diligence measures, including in relation to politically exposed persons, and simplified due diligence only where permitted.
  • Relevant persons must keep records adequate to demonstrate compliance with CDD, transaction and reporting requirements.
  • Relevant persons must maintain systems and internal reporting procedures to identify and report suspicious activity.
  • Relevant persons must maintain an independent audit function to test AML/ATF systems and controls.
  • Relevant persons must provide training to relevant staff on AML/ATF obligations.
  • Relevant persons must appoint a Compliance Officer and a Reporting Officer to carry out the functions specified in the Regulations.
  • Payment service providers must ensure transfers of funds are accompanied by required payer and payee information and must detect and act on missing or incomplete information, including reporting where this makes a transaction suspicious.
  • Casino operators must comply with specific timing-of-verification and patron account rules, and must not conduct prohibited transactions.
  • Dealers in high value goods must be registered with the Registrar to fall within scope, and must apply CDD once occasional transaction thresholds are met.

Applies to

AML/ATF regulated financial institutions, independent professionals (legal advisers and accountants), casino operators, dealers in high value goods registered with the Registrar, real estate brokers and real estate agents, members of financial groups, payment service providers, digital asset businesses

Related documents

Topics

Version history

2026-09-08

source file (current)

2026-07-07

source file

2026-07-07

source file