Statement of Guidance

Anti-Money Laundering & Combatting Terrorist Financing Guidelines for the Banking Sector

British Virgin Islands Financial Services Commission (FSC) · British Virgin Islands

In force

Published: 2020-07-01

Current version last checked: 2026-07-27

Summary

These are FSC guidelines that supplement the BVI's AML/CFT legislative framework (the Proceeds of Criminal Conduct Act 1997, Anti-Money Laundering Regulations 2008, and the AML/TF Code of Practice 2008) with practical guidance specifically for banks licensed under the Banks and Trust Companies Act, 1990. They explain money laundering, terrorist financing and proliferation financing risks and set out the FSC's expectations for how banks should design and operate their AML/CFT programmes. The guidelines are not a substitute for the underlying legislation and must be read alongside it.

  • Risk-based approach: Banks must identify, assess, manage and mitigate their ML/TF/PF risks and demonstrate that their risk-based approach is effective.
  • Governance and internal controls: Banks must maintain adequate internal controls, governance arrangements and an independent internal audit function to test their AML/CFT programme.
  • MLRO: Banks must appoint a Money Laundering Reporting Officer responsible for AML/CFT compliance and liaison with the Financial Investigation Agency (FIA).
  • Customer due diligence: Banks must conduct CDD and enhanced CDD, verify customer identity (including legal persons, arrangements and persons acting on behalf of others), and apply ongoing CDD and monitoring.
  • Wire transfers and correspondent banking: Banks must apply specific controls to cross-border and domestic wire transfers and to correspondent banking relationships given their heightened risk.
  • Suspicious activity reporting: Banks must recognise indicators of suspicious activity and report suspicions (SARs/STRs) in accordance with the regime.
  • Record keeping: Banks must retain transaction records, CDD records, SAR/STR records and training records for the periods and in the formats required.
  • Employee screening, training and testing: Banks must screen employees, provide continuous AML/CFT training (at least annually) to staff, temporary/contracted employees and outsourced third parties, test employees' understanding, and maintain training records.
  • Reporting terminations: Banks must inform the FSC and the FIA if an employee's contract is terminated for lack of AML/CFT compliance or lack of probity.

The guidelines close with a reminder that banks are expected to have read and to apply them appropriately as part of the Territory's overall effort to detect, prevent and combat money laundering and terrorist financing.

Key obligations

  • Banks must implement and maintain a risk-based approach to identifying, assessing, managing and mitigating ML/TF/PF risks
  • Banks must appoint a Money Laundering Reporting Officer (MLRO) responsible for AML/CFT compliance and liaison with the FIA
  • Banks must conduct customer due diligence (CDD) and, where required, enhanced CDD, including verification of identity for legal persons, arrangements and agents
  • Banks must apply ongoing CDD and ongoing monitoring throughout the business relationship
  • Banks must resolve customer identity verification within 30 days or take appropriate action if unable to verify
  • Banks must apply specific controls to cross-border and domestic wire transfers and correspondent banking relationships
  • Banks must recognise and report suspicious activity/transactions (SARs/STRs)
  • Banks must maintain records of transactions, CDD, SARs/STRs and training in the required format and for the required retention period
  • Banks must screen employees and provide AML/CFT training at least annually to staff, temporary/contracted employees and outsourced third parties, and test their understanding
  • Banks must maintain records of all staff training including date, nature, topics, duration and trainee names
  • Banks must inform the FSC and FIA if an employee's contract is terminated for lack of AML/CFT compliance or probity
  • Banks must undertake independent internal audits of their AML/CFT programme and report deficiencies to the Board of Directors

Applies to

banks

Deadlines

  • 30 days: Period within which a bank must verify a customer's identity before further action is required if verification cannot be completed
  • at least once a year: Minimum frequency required for ongoing AML/CFT employee training

Topics

Version history

2026-07-11

source file (current)