Key Takeaways
- AML and KYC obligations in Anguilla rest on the legal framework set out in POCA, the AML/CFT Regulations, and the AML/CFT Code.
- Businesses falling within scope must apply customer due diligence, conduct enhanced checks in higher-risk situations, and keep prescribed records.
- Suspicious activity must be reported to the Financial Intelligence Unit, and the registered agent plays a defined role in maintaining compliance.
- Failing to meet these requirements can expose a foreign-owned company to penalties for non-compliance.
AML and KYC Obligations in Anguilla: An Overview
AML/KYC in Anguilla refers to the anti-money-laundering and know-your-customer duties that licensed and registered service providers must apply to the customers and structures they serve. These obligations rest on the Proceeds of Crime Act and its supporting Regulations and Code, and they are supervised by the Anguilla Financial Services Commission, with the Financial Intelligence Unit receiving suspicious activity reports through its legal frameworks portal.
If you own an Anguilla company from abroad, the practical weight of these rules falls on your registered agent rather than on you directly. This article explains how the framework works, who it binds, what due diligence and record-keeping it demands, and what happens when it is breached. It is written for non-resident owners, investors, and advisers who need their Anguilla entity to remain in good standing.
The Legal Framework: POCA, the AML/CFT Regulations, and the AML/CFT Code
Anguilla built its AML/CFT regime to meet international standards, with the Proceeds of Crime Act strengthened in 2009 as the centrepiece. POCA is codified as R.S.A. c. P98 and sits above two subsidiary instruments that fill in the operating detail.
Those instruments are the Anti-Money Laundering and Terrorist Financing Regulations and the Anti-Money Laundering and Terrorist Financing Code, both carried as R.R.A. P98. Between them, they set out customer due diligence, record-keeping, reporting, and supervision in workable terms.
The framework is not static. Amendments include the Anti-Money Laundering and Terrorist Financing (Amendment) Regulations, R.A. 24 of 2018, and a further set of changes effective December 2022 that added a fallback rule for identifying beneficial owners, which is discussed below.
Separate rules govern virtual-asset activity, including the Utility Token Offering Regulations (R.A. 85 of 2020) and the Utility Tokens Exchange Regulations (R.A. 90 of 2020). Both POCA and the Code define a "document" broadly, capturing any record of information whether stored on paper, electronically, or on discs and tapes.
Primary AML/CFT legislation, including the full POCA text, is published on the Anguilla FIU site. Use it to verify section numbers before relying on any summary.
As a member of the Caribbean Financial Action Task Force (CFATF), the jurisdiction is assessed against the FATF 40 Recommendations, which is why much of the regime tracks international norms rather than purely local custom.
Company Incorporation in Anguilla
Set up your company in Anguilla with Expanship handling registration end to end.
Who Supervises AML/CFT Compliance in Anguilla
The Anguilla Financial Services Commission is the primary AML/CFT supervisor. Established under the Financial Services Commission Act, which was enacted on 26 November 2003 with operations commencing on 2 February 2004, the Commission is an autonomous authority responsible for regulating, supervising, and inspecting financial services in and from within the territory.
Its AML/CFT remit reaches widely. The Commission supervises insurance, offshore banking, trust business, company management, mutual funds, money services businesses, utility tokens, and utility token exchanges, and it also covers non-profit organisations and externally and non-regulated service providers.
Domestic banks fall under the Commission for AML/CFT purposes, even though their prudential licensing sits with a separate authority. The Commission also operates the registration system for externally regulated and non-regulated service providers, requiring any person carrying on a relevant business in or from within the islands to apply for the appropriate status.
A second body completes the picture. The Financial Intelligence Unit, reachable at fiu.gov.ai, receives suspicious activity reports and maintains the legislation portal, while the Commission's own portal at fsc.org.ai carries supervisory guidance.
Which Businesses and Activities Fall Within Scope
Scope is defined by Schedule 2 of the AML/CFT Regulations, which lists the "relevant business" categories that trigger AML obligations. The list captures the financial sector and reaches beyond it.
In-scope activities confirmed from official sources include:
- Banks, both offshore and domestic
- Trust companies and offshore banking licensees under the Trust Companies and Offshore Banking Act
- Company management and corporate service providers
- Insurance businesses and mutual fund administrators
- Money services businesses
- Securities licensees under Parts 4 and 9 of the Securities Act
- Independent legal professionals carrying out transactions such as real-estate or business-entity transfers, handling client money, or forming companies, trusts, and foundations
- Non-profit organisations
- Utility token offering participants and utility token exchanges
Externally regulated service providers (ERSPs) and non-regulated service providers (NRSPs) sit within this structure too. The amendments in force from 25 September 2013 define ERSPs as holders of a Banking Act licence or a licence under Part 4 or Part 9 of the Securities Act, and the Commission, acting as NRSP Supervisor, maintains a register of non-regulated providers.
A point on thresholds: the precise monetary figure above which one-off transactions require standard CDD is not published in the sources reviewed. FATF-aligned regimes commonly apply due diligence to occasional transactions at or above USD 15,000 equivalent, but for the exact Anguilla figure you should consult Schedule 2 of the Regulations and the Code directly.
Ongoing Compliance in Anguilla
Keep your Anguilla entity compliant with filings, returns, and statutory obligations.
KYC and Customer Due Diligence Requirements
Customer due diligence under the AML/CFT Code follows a risk-based approach consistent with FATF Recommendations. A service provider must identify and verify the customer at the start of a relationship and keep that knowledge current on a risk-sensitive basis as the relationship continues.
For a foreign-owned company, the most consequential rule is this: where a trust and corporate service provider acts as your registered agent, the company, limited partnership, or foundation is itself a customer of that agent. The agent must therefore apply full CDD to the very entity it represents, including its beneficial owners.
The December 2022 amendments added a practical safeguard. Where a provider has exhausted all means of identifying the beneficial owner, it must instead identify and verify the individual holding the position of senior managing official, ensuring no structure escapes a named responsible person.
CDD records carry a minimum retention period of five years for entities not covered by a specific sector Act, governed by Sections 35 to 39 of the Code together with the record-accessibility rules in Section 9 of the Regulations. The published guidance on those sections sets the standard for how documentation must be stored and made available.
The exact KYC document checklist is not specified in the public sources reviewed. In practice, FATF-compliant jurisdictions expect government-issued photo identification, proof of residential address, and source-of-funds or source-of-wealth evidence for individuals, plus constitutional documents and ownership registers for legal entities. Your registered agent will issue its own document request based on the Commission's guidance.
Enhanced Due Diligence and Higher-Risk Situations
Certain relationships demand more than standard checks. The Code requires enhanced due diligence wherever the risk profile is elevated, and several higher-risk categories are confirmed in official guidance.
- Politically exposed persons, referenced in the Commission's beneficial-ownership guidance
- Non-resident customers and cross-border structures
- Non-profit organisations, singled out for heightened attention
- Utility token and virtual-asset businesses under the 2020 Regulations
- Entities where a corporate service provider acts as registered agent, treated as customers requiring elevated scrutiny where risk warrants
The operative EDD measures track international practice: verifying source of wealth and source of funds, obtaining senior-management approval to proceed, and applying closer ongoing monitoring with more frequent review. The specific Code sections that set out these steps are not confirmed in the sources reviewed, so the Code itself should be consulted for the exact provisions.
Anguilla Incorporation Pricing
See transparent pricing to incorporate and maintain a company in Anguilla.
Ongoing Monitoring of Business Relationships
Due diligence does not end at onboarding. The risk-based framework requires service providers to monitor each relationship continuously against the customer's known profile, and the Commission's guidance confirms that CDD must be maintained on a risk-sensitive basis throughout.
Several events should prompt a provider to refresh or escalate its checks. Material changes in a customer's risk profile, transactions that are unusual or inconsistent with expected activity, and requests from regulators all count as triggers.
Underlying this is a standing duty of care over records: companies and their agents must take reasonable precautions against the loss, destruction, or falsification of any document. Precise monitoring frequencies and transaction-screening thresholds are not fixed by published figures; the intensity is calibrated to risk rating, transaction volume, and jurisdictional exposure.
AML Record-Keeping Obligations
The headline rule is a five-year minimum retention period for accounting records, applied to entities not covered by a specific sector Act under POCA, the Regulations, and the Code. CDD records sit under Section 9 of the Regulations, which requires that they be held in a way that promotes accessibility, retention, and appropriate security.
Format is flexible. Records may be kept on paper, electronically, magnetically, or in any non-paper form, including discs and tapes.
Storage outside the islands is permitted, but only subject to the Commission's accessibility requirements. The guidance notes flag a real risk: confidentiality rules or data-protection restrictions in the overseas country can impede access, so offshore storage must not put records beyond reach.
| Element | Requirement |
|---|---|
| Minimum retention | Five years (entities outside specific sector Acts) |
| Governing provisions | POCA; Code Sections 35–39; Regulations Section 9 |
| Permitted formats | Paper, electronic, magnetic, disc, tape |
| Overseas storage | Allowed if accessibility is preserved |
| Duty of care | Prevent loss, destruction, or falsification |
What must be kept includes CDD and KYC files, transaction records, SAR-related material, training records, and correspondence with the Commission and the FIU. Whether the five-year clock runs from the last transaction or from the end of the relationship is not stated in the Anguilla sources reviewed; FATF-aligned regimes generally measure from whichever of those dates is later, and the Code should be checked for the precise rule.
Suspicious Activity Reporting to the Financial Intelligence Unit
Suspicious activity reports go to the Anguilla Financial Intelligence Unit at fiu.gov.ai. POCA and the Code impose the duty: a reporting entity must file a SAR when it knows or has reasonable grounds to suspect that funds or a transaction are linked to money laundering or terrorist financing.
There is no minimum amount. Suspicion alone triggers the obligation, regardless of transaction size.
Two related prohibitions matter. Tipping off, meaning disclosing to a customer or third party that a SAR has been filed or an investigation is underway, is a separate criminal offence, and SARs themselves are held confidentially by the FIU, with disclosure outside the Unit requiring the Director's approval.
The reporting duty binds all financial service providers as well as non-profit organisations and externally and non-regulated providers. The exact submission mechanism and any statutory filing deadline are not confirmed in the public sources reviewed; CFATF practice points to filing as soon as practicable, and the precise channel should be confirmed with the FIU directly. For a non-resident owner, this is the one obligation least likely to involve you personally, since your registered agent or service provider files where required.
The Role of the Registered Agent in AML Compliance
Every Anguilla company must keep a locally licensed registered agent, and that agent is the practical engine of your AML compliance. Filings must be made by the registered agent, which concentrates responsibility in a single licensed party.
The agent's duty runs deeper than administration. When a trust and corporate service provider acts as registered agent, your entity is its customer, so the agent must apply full CDD to the company, its owners, and its controllers, and keep that diligence current.
Registered agents that are trust and company service providers are licensed under the Trust Companies and Offshore Banking Act and supervised by the Commission for both prudential and AML purposes. They carry the fallback obligation from the December 2022 amendments: if your ultimate beneficial owner cannot be identified after all reasonable means are exhausted, the agent must record the senior managing official instead.
A consequence for foreign owners follows directly. You cannot substitute your own internal KYC for the agent's licensed process; expect to provide identification, ownership evidence, and source-of-funds material on request, and to refresh it as circumstances change.
Penalties for Non-Compliance
Enforcement runs through POCA, the Regulations, and the Code, with the Commission holding supervisory powers over every entity in its remit. Money laundering as a substantive offence carries criminal penalties, meaning imprisonment, fines, or both.
The exact quantum for Anguilla is not published in the sources reviewed. Across Caribbean POCA statutes, maximum custodial terms commonly fall between 14 and 20 years with substantial fines for individuals and corporations, but the precise figures should be read from the Act itself.
Specific failures attract specific exposure:
- Failing to file a SAR is a criminal offence under POCA, and tipping off is a separate offence
- Failing to keep records for the five-year minimum is an offence under POCA and the Code
- A registered agent that does not conduct CDD on its clients, including the entities it acts for, risks licence suspension or revocation alongside civil or criminal liability
- Operating a relevant business as an unregistered NRSP is an offence under the ENRSP Regulations
Administrative penalty amounts and any escalation schedule applied by the Commission are not set out in the public sources reviewed; the Commission's enforcement and sanctions policy should be requested from fsc.org.ai. Because all company filings must pass through the registered agent, failures attach first to that agent, giving the regulator a concentrated point of enforcement.
Conclusion
For a non-resident owner, AML/KYC in Anguilla is largely a duty discharged on your behalf by a licensed registered agent, and your obligation is to feed that agent accurate, current information rather than to file anything yourself. The framework is risk-based and FATF-aligned, so the burden scales with how complex or high-risk your structure looks.
The sensible next step is to confirm what CDD and source-of-funds evidence your registered agent expects and to keep it refreshed, since gaps in that chain are what expose both the agent and your company.
How Expanship Can Help Your Business in Anguilla
Expanship supports foreign owners in meeting AML/KYC expectations by acting as or coordinating with a licensed registered agent, assembling the due diligence record your structure requires, and keeping that file current as ownership or activity changes. The same team manages the wider compliance demands a foreign-owned entity faces in the territory.
- Company formation and structuring for non-resident owners
- Licensed registered agent and registered office services
- Ongoing compliance and filing management with the Commission and FIU
- Accounting and bookkeeping aligned with record-retention rules
- Economic-substance and beneficial-ownership reporting support
- Banking introductions for newly formed entities
To discuss your requirements, contact Expanship Anguilla.
Frequently Asked Questions
The obligations bind licensed and registered service providers, not the foreign shareholder directly, so your registered agent performs the due diligence. In practice this means you must supply identification, ownership evidence, and source-of-funds material when asked, because your entity is treated as the agent's customer under Section 14 of the AML/CFT framework.
The minimum retention period is five years for accounting records of entities not covered by a specific sector Act, under POCA and the AML/CFT Code. The clock is generally measured from the last transaction or the end of the relationship, though the precise reference point should be confirmed against the Code's Sections 35 to 39.
The Anguilla Financial Services Commission is the primary supervisor for all financial service providers, externally and non-regulated providers, and non-profit organisations. The Financial Intelligence Unit, separately, receives suspicious activity reports and maintains the legislation portal at fiu.gov.ai.
No. A report must be filed whenever a reporting entity knows or has reasonable grounds to suspect a link to money laundering or terrorist financing, regardless of the transaction value.
Yes, overseas storage is permitted, but only if the records remain accessible to the Commission. Confidentiality or data-protection rules in the foreign country must not place the records beyond reach, so practical accessibility has to be preserved.
A registered agent that does not conduct proper CDD on the entities it acts for risks licence suspension or revocation, plus civil or criminal liability under POCA. Because all company filings pass through the agent, enforcement attaches first to that agent, which is why choosing a diligent provider directly affects your company's standing.
Legal Disclaimer
The information provided in this article is for general informational purposes only and does not constitute legal, tax, or professional advice. While we strive to ensure the accuracy and timeliness of the content, laws and regulations are subject to change, and the application of laws can vary widely based on specific facts and circumstances.
Readers should not act upon this information without seeking professional counsel tailored to their individual situation. Expanship and its authors disclaim any liability for actions taken or not taken based on the content of this article.
For specific advice regarding your business setup, compliance requirements, or any legal matters, please consult with qualified legal and tax professionals in the relevant jurisdiction.