Bermuda
AML/CFT
227 Bermuda regulatory document(s) tagged AML/CFT.
Who is caught
Bermuda's AML/CFT framework is built on three principal statutes -- the Proceeds of Crime Act 1997, the Anti-Terrorism (Financial and Other Measures) Act 2004, and the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 -- with the detailed customer-facing obligations set out in the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008. The Bermuda Monetary Authority (BMA) is the primary supervisory authority, alongside sector-specific supervisors and the Financial Intelligence Agency (FIA).
Scope turns on being an AML/ATF regulated financial institution or a designated non-financial business or profession. The Proceeds of Crime Act 1997 (Schedule 3) lists the financial activities (deposit-taking, lending, money or value transfer, payment services, securities dealing, portfolio management, safekeeping, insurance underwriting, currency exchange and similar) that bring a person within the definition of an AML/ATF regulated financial institution.
- Financial institutions: Deposit-taking businesses, insurers carrying on long-term business, insurance managers and brokers, money service businesses, trust businesses, fund administrators, investment businesses and fund operators are designated as regulated-sector businesses under the 2008 Order and related legislation.
- Digital and virtual asset firms: Licensed digital asset businesses and virtual currency businesses are designated AML/ATF regulated financial institutions under their respective 2018 Acts and consequential amendments.
- Corporate service providers: Persons carrying on corporate service provider business are treated as AML/ATF regulated financial institutions under the Corporate Service Provider Business Act 2012 and related regulations.
- Designated non-financial businesses: Casino operators, dealers in high value goods (accepting cash payments of BMD 7,500 or more), and real estate brokers and agents are regulated non-financial businesses under the 2008 Act and the 2008 Regulations.
- Independent professionals: Barristers and accountants acting in that capacity are covered, supervised by the Barristers and Accountants AML/ATF Board designated under the 2012 Designation Order.
- Individuals generally: The criminal money laundering and terrorist financing offences in the Proceeds of Crime Act 1997 and the Anti-Terrorism (Financial and Other Measures) Act 2004 apply to any person, not only regulated firms.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Designation Order 2012 (BR 64/2012) · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Corporate Service Provider Business Act 2012 · Digital Asset Business Act 2018 · Virtual Currency Business Act 2018
Key duties
Continuing obligations fall into two layers: the customer due diligence and internal-controls duties imposed on all relevant persons by the 2008 Regulations, and sector-specific licensing, registration and reporting duties administered by the BMA and other supervisors.
Customer due diligence
- Identify and verify: Relevant persons must identify and verify customers and beneficial owners using reliable independent sources, and understand ownership and control structures, generally applying a 25 percent ownership or control threshold (10 percent for corporate service providers).
- Risk-based measures: Simplified or enhanced due diligence must be applied according to risk, with enhanced measures for higher-risk situations including politically exposed persons and their family members and close associates.
- Ongoing monitoring: Relevant persons must conduct ongoing monitoring of business relationships and transactions.
- Wire transfers: Payment service providers must obtain, verify, retain and pass on payer and payee information accompanying transfers of funds, and act on and report missing or incomplete information.
Governance and records
- Compliance and Reporting Officers: Relevant persons must establish internal systems, controls and reporting procedures and designate a Compliance Officer and a Reporting Officer.
- Training and audit: AML/ATF training must be provided to relevant staff, and an independent audit function maintained where applicable.
- Record-keeping: Records of customer due diligence and transactions must be kept as required under the Regulations; several codes and rules require records to be kept in Bermuda and retained for five years.
Registration and licensing
- Licences: Corporate service providers, digital asset businesses, virtual currency businesses and money service businesses must be licensed by the BMA before carrying on the regulated activity.
- Registration: Non-licensed AML/ATF regulated financial institutions and regulated non-financial businesses must apply for and maintain registration with their supervisory authority, subject to fit and proper testing.
- Codes of practice: Licensees must have regard to the BMA's codes of practice and codes of conduct, which require compliance with the Proceeds of Crime Act 1997, the AML/ATF Regulations 2008 and the Anti-Terrorism Act 2004; non-compliance is weighed in assessing prudent conduct.
Reporting and notifications
- Suspicion disclosure: Persons who know or suspect money laundering or terrorist financing must disclose promptly to the FIA, subject to legal professional privilege exceptions.
- Annual returns with AML content: Digital asset businesses, virtual currency businesses, insurers, insurance managers, insurance brokers and agents, and insurance marketplace providers must file annual returns that include AML/ATF and sanctions schedules; insurance brokers, agents and marketplace providers file on or before 30 June each year, and virtual currency businesses file within four months of their financial year-end.
- FIA notices: An institution served with an FIA freezing notice must not make funds available to the specified person for up to 72 hours, and any person served with an FIA information notice must provide the required information.
- Account monitoring orders: A financial institution served with an account monitoring order under the Anti-Terrorism Act must provide specified account information for a period not exceeding 90 days.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Financial Intelligence Agency Act 2007 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Corporate Service Provider Business Act 2012 · Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Money Service Business Act 2016 · Digital Asset Business Act 2018 · Digital Asset Business (Prudential Standards) (Annual Return) Rules 2018 (BR 98 / 2018) · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Banks and Deposit Companies Act 1999 - Code of Conduct (August 2022) · Banks and Deposit Companies Code of Conduct (August 2022) · Code of Practice - Money Service Business Act 2016 · Digital Asset Business - Code of Practice (February 2024) · Digital Asset Business (Prudential Standards) (Annual Return) Rules 2018 · CSP - Code of Practice (September 2019) · Code of Practice Virtual Currency Business Act 2018 · Virtual Currency Business (Prudential Standards) (Annual Return) Rules 2018 · Virtual Currency Business Act 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Insurance Manager Code of Conduct 2016
Exemptions and carve-outs
The instruments provide a mix of scope carve-outs, licensing exemption powers, and reduced obligations for lower-risk cases.
- Schedule 3 exceptions: The Proceeds of Crime Act 1997 lists exceptions to the specified financial activities that define an AML/ATF regulated financial institution, including certain intra-group transactions, certain insurance ancillary business, and real estate deposit-taking.
- Licensing exemption orders: The digital asset business, virtual currency business and money service business regimes each operate subject to any exemption order that may remove a person from the licensing requirement.
- Trust business: Trust business is designated as regulated-sector business under the 2008 Order unless exempted under the related 2003 Exemption Order.
- Simplified due diligence: The 2008 Regulations permit simplified due diligence in lower-risk situations as an alternative to standard measures.
- Reduced AML return content: An insurance broker, agent or marketplace provider that is not an AML/ATF regulated financial institution need only complete the corporate governance section of the AML/ATF questionnaire in its annual return.
- Digital asset issuance: Under the Digital Asset Issuance Rules 2020, issuers relying on an accredited digital asset business, qualifying as a local issuer, or authorised or vetted by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.
- Legal privilege: The disclosure duties under the Anti-Terrorism Act and the Proceeds of Crime Act are subject to legal professional privilege exceptions.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 · Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 · Financial Intelligence Agency Act 2007 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Money Service Business Act 2016 · Digital Asset Business Act 2018 · Digital Asset Issuance Rules 2020 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019)
Enforcement and penalties
Enforcement combines criminal offences under the primary statutes, supervisory and disciplinary powers exercised by the BMA and other authorities, and specific offences attached to FIA notices.
Criminal offences
- Money laundering and terrorist financing: The Proceeds of Crime Act 1997 and the Anti-Terrorism Act 2004 create offences for laundering, concealing, transferring, acquiring or using criminal or terrorist property, tipping-off, prejudicing an investigation, and failing to comply with directions, production orders or search warrants.
- Unlicensed activity: Carrying on corporate service provider business without a licence is an offence carrying up to a $25,000 fine or one year's imprisonment on summary conviction, and up to a $100,000 fine or five years on indictment; unlicensed money service, digital asset and virtual currency business are also offences.
- FIA notices: Breach of an FIA freezing notice without reasonable excuse carries a $50,000 fine; failure to comply with an information notice carries a $10,000 fine and/or six months' imprisonment; unauthorised disclosure of restricted information carries a $50,000 fine and up to two years' imprisonment.
Supervisory and civil sanctions
- BMA disciplinary powers: Under the sector Acts and the 2008 Supervision and Enforcement Act, competent authorities may impose civil penalties, issue public censures, make prohibition orders, seek injunctions, issue directives, restrict or revoke licences, and petition for winding up, with warning and decision notice procedures and a right of appeal to a tribunal and ultimately the Supreme Court.
- Investigation powers: Competent authorities may require information and documents, conduct site visits, and enter premises under warrant, with offences for failing to comply.
- Late filing penalty: A virtual currency business that fails to file required audited financial statements, accounts, or returns within the four-month deadline is liable to a civil penalty of up to $5,000 per week or part-week of default.
- Codes: Non-compliance with the BMA's codes of practice and conduct is not itself an offence but is taken into account in assessing whether a business is conducted prudently and may trigger formal enforcement action.
Sources: Proceeds of Crime Act 1997 · Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing Supervision and Enforcement) Act 2008 · Financial Intelligence Agency Act 2007 · Anti-Terrorism (Financial and Other Measures) Act 2004 · Corporate Service Provider Business Act 2012 · Money Service Business Act 2016 · Digital Asset Business Act 2018 · Code of Practice - Money Service Business Act 2016 · Digital Asset Business - Code of Practice (February 2024) · CSP - Code of Practice (September 2019) · Code of Practice Virtual Currency Business Act 2018 · Virtual Currency Business Act 2018 · Digital Asset Business Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023)