Bermuda
AML/CFT
229 Bermuda regulatory document(s) tagged AML/CFT.
Who is caught
Bermuda's AML/CFT framework rests on four core instruments: the Proceeds of Crime Act 1997, the Anti-Terrorism (Financial and Other Measures) Act 2004, the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008, and the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008. These apply to persons treated as AML/ATF regulated financial institutions and to designated non-financial businesses and professions carrying on business in or from Bermuda.
Financial institutions
- Specified financial activities: Schedule 3 to the Proceeds of Crime Act 1997 lists the activities that bring a person within the definition of an AML/ATF regulated financial institution, including deposit-taking, lending, money or value transfer, payment services, securities dealing, portfolio management, safekeeping, insurance underwriting and currency exchange.
- Regulated sector classes: The Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 treats deposit-taking business, investment business, long-term insurers (not reinsurers), insurance managers and brokers (in connection with long-term business), fund administrators, money service businesses, trust businesses and investment fund operators as being in the regulated sector, with the BMA as supervisory authority.
- Licensed sectors: Corporate service providers, digital asset businesses and money service businesses are designated as AML/ATF regulated financial institutions by their respective licensing statutes (Corporate Service Provider Business Act 2012, Digital Asset Business Act 2018, Money Service Business Act 2016).
Non-financial businesses
- DNFBPs: The Proceeds of Crime (AML/ATF Supervision and Enforcement) Act 2008 and the Regulations 2008 also capture casino operators, dealers in high value goods accepting cash payments of BMD 7,500 or more, and real estate brokers and agents.
- Independent professionals: Barristers and accountants acting in that capacity are within scope, supervised by the Barristers and Accountants AML/ATF Board designated under the 2008 Act.
Separately, the criminal offences created by the Anti-Terrorism (Financial and Other Measures) Act 2004 and the Proceeds of Crime Act 1997 (money laundering, terrorist financing, tipping-off) apply to persons generally, not only to the regulated sector.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Designation Order 2012 (BR 64/2012) · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Corporate Service Provider Business Act 2012 · Money Service Business Act 2016 · Digital Asset Business Act 2018
Key duties
The continuing operational obligations sit principally in the Proceeds of Crime (AML/ATF) Regulations 2008, supplemented by registration and reporting duties under the sector statutes and annual-return rules.
Registration and licensing
- Registration: Non-licensed AML/ATF regulated financial institutions and regulated non-financial businesses or professions must apply for and maintain registration with their supervisory authority, subject to fit and proper testing, under the 2008 Act.
- Licensing: Corporate service providers, digital asset businesses and money service businesses must be licensed by the BMA before carrying on the regulated activity, and licence applications for money service businesses must include AML/ATF policies and procedures.
Customer due diligence
- CDD and beneficial ownership: Relevant persons must identify and verify customers and beneficial owners and identify the natural person acting as chief executive for legal entities, generally applying a 25% ownership or control threshold (reduced to 10% for corporate service providers).
- Ongoing monitoring: Relevant persons must conduct ongoing monitoring of business relationships.
- Risk-based measures: Enhanced due diligence is mandatory in higher-risk cases including politically exposed persons; simplified due diligence applies only where permitted.
Internal controls and governance
- Officers: Relevant persons must appoint a Compliance Officer and a Reporting Officer.
- Systems and audit: They must maintain internal reporting procedures, an independent audit function to test AML/ATF systems and controls, and provide staff training.
- Record-keeping: Records adequate to demonstrate compliance with CDD, transaction and reporting requirements must be kept.
Wire transfers
Under Part 4 of the Regulations 2008, payment service providers must ensure transfers of funds are accompanied by the required payer and payee information, detect and act on missing or incomplete information, and report where this makes a transaction suspicious.
Disclosure to the FIA
- Suspicion reporting: Persons who know or suspect money laundering or terrorist financing must disclose it to the Financial Intelligence Agency under the Proceeds of Crime Act 1997 and the Anti-Terrorism (Financial and Other Measures) Act 2004, subject to legal privilege exceptions, and must not tip off.
- Supervisor reporting: A supervisory authority that suspects money laundering or terrorist financing must inform the FIA as soon as practicable under the 2008 Act.
Proliferation financing
The Proceeds of Crime (AML/ATF) Amendment Regulations 2026, effective 22 June 2026, extend existing risk assessment, policy, control, training, officer, reporting and record-keeping obligations to also cover proliferation financing (counter-proliferation financing).
Annual returns and deadlines
- Insurers: Insurers must file a statutory financial return under the Insurance Returns and Solvency Regulations 1980, including the Schedule IV AML/ATF reporting on compliance officer oversight, risk assessments and programme reviews.
- Insurance brokers and agents: Registered insurance brokers and agents must file an annual return by 30 June each year (including AML/ATF and sanctions schedules) and retain a copy at their principal office for five years.
- Insurance marketplace providers: Insurance marketplace providers must file an annual return by 30 June each year with AML/ATF and sanctions content, retained for five years.
- Insurance managers: Insurance managers must submit an annual return covering a detailed AML/ATF questionnaire and corporate governance confirmations.
- Digital asset businesses: Licensed digital asset businesses must file an annual return under the Digital Asset Business (Prudential Standards) (Annual Return) Rules 2018 including Schedule II AML/CFT data (SAR filings, PEP and sanctions screening, GoAML registration), with a signed director declaration.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Corporate Service Provider Business Act 2012 · Insurance Returns and Solvency Regulations 1980 · Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Money Service Business Act 2016 · Digital Asset Business Act 2018 · Digital Asset Business (Prudential Standards) (Annual Return) Rules 2018 (BR 98 / 2018) · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Digital Asset Business (Prudential Standards) (Annual Return) Rules 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Amendment Regulations 2026
Exemptions and carve-outs
The instruments provide several carve-outs, mostly by narrowing what falls within the definition of a regulated activity or by scaling obligations to risk.
- Schedule 3 exceptions: The Proceeds of Crime Act 1997 lists exceptions to the specified financial activities that bring a person within scope, including intra-group transactions, certain insurance ancillary business and real estate deposit-taking.
- Trust business: Trust businesses are in the regulated sector under the 2008 Order unless exempted under the related 2003 Exemption Order.
- Dealers in high value goods: Dealers in high value goods only fall within scope, and need only apply CDD, once cash occasional transaction thresholds (BMD 7,500) are met, and must be registered with the Registrar.
- Simplified due diligence: The Regulations 2008 permit simplified due diligence in defined lower-risk situations rather than full CDD.
- Reduced AML return content: Insurance brokers, agents and marketplace providers that are not AML/ATF regulated financial institutions need only complete the corporate governance section of the AML/ATF schedule in their annual return, rather than the full questionnaire.
- Licensing exemption orders: The Digital Asset Business Act 2018 and the Money Service Business Act 2016 make the licensing requirement subject to any exemption order; the Money Service Business Act does not apply to institutions licensed under the Banks and Deposit Companies Act 1999.
- Legal privilege: The disclosure duties under the Anti-Terrorism (Financial and Other Measures) Act 2004 and the Financial Intelligence Agency Act 2007 do not override legal professional privilege.
The digital asset issuance regime also provides reduced rule sets for issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised by another competent authority, but an exemption form must be filed with the Authority before proceeding.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 · Financial Intelligence Agency Act 2007 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Money Service Business Act 2016 · Digital Asset Issuance Rules 2020 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019)
Enforcement and penalties
Enforcement runs on two tracks: supervisory and disciplinary powers exercised by the BMA and other supervisory authorities, and criminal offences under the underlying statutes.
Supervisory enforcement
- 2008 Act powers: Under the Proceeds of Crime (AML/ATF Supervision and Enforcement) Act 2008, competent authorities may impose civil penalties, issue directives, restrict or revoke licences, issue public censures and prohibition orders, seek injunctions, and petition for winding up, with a right of appeal to an appeal tribunal and ultimately the Supreme Court.
- Civil penalty caps: The BMA's Enforcement Guide (September 2018) sets a four-step civil penalty process and caps prudential penalties at 500,000 dollars and penalties under the Supervision and Enforcement Act at 10 million dollars.
- Sector statute powers: The Corporate Service Provider Business Act 2012, Digital Asset Business Act 2018 and Money Service Business Act 2016 each give the BMA powers to impose civil penalties, issue public censures, make prohibition orders, restrict or revoke licences and issue warning and decision notices.
- Codes of practice: Non-compliance with the BMA's codes of practice is not itself an offence but is taken into account in assessing whether a business is conducted prudently and may lead to enforcement action.
Criminal offences
- Money laundering and terrorist financing: The Proceeds of Crime Act 1997 and the Anti-Terrorism (Financial and Other Measures) Act 2004 create criminal offences for money laundering, terrorist financing, tipping-off, and failure to comply with directions, production orders or account monitoring orders.
- Breach of the Regulations: Breach of specified requirements in Parts 3 and 4 of the Proceeds of Crime (AML/ATF) Regulations 2008 constitutes an offence.
- Unlicensed activity: Carrying on corporate service provider business without a licence is an offence carrying up to a 25,000 dollar fine or one year's imprisonment on summary conviction, and up to a 100,000 dollar fine or five years on indictment.
- FIA notices: Under the Financial Intelligence Agency Act 2007, breach of a freezing notice carries a 50,000 dollar fine, breach of an information notice a 10,000 dollar fine and/or six months' imprisonment, and unauthorised disclosure of restricted information a 50,000 dollar fine and up to two years' imprisonment.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Financial Intelligence Agency Act 2007 · Corporate Service Provider Business Act 2012 · Enforcement Guide: Statement of Principles & Guidance on the Exercise of Enforcement Powers (September 2018)