Listen to this article
0:00 / 0:00

Key Takeaways

  • AML and KYC obligations in Bermuda sit within the POCA and AML/ATF regulatory framework, with supervisors and the Financial Intelligence Agency overseeing compliance.
  • Regulated persons must carry out customer due diligence, apply enhanced or simplified measures based on risk, and monitor business relationships on an ongoing basis.
  • Firms are required to keep AML records, report suspicious activity to the FIA, and maintain internal controls including a compliance officer and an MLRO.
  • Non-compliance can lead to offences, penalties, and enforcement action, while the registered agent plays a defined role in supporting AML and KYC duties.

AML/KYC in Bermuda is the set of anti-money-laundering and know-your-customer duties that regulated businesses must apply when they take on clients, monitor activity, and report suspicions. The regime rests on the Proceeds of Crime Act 1997 and the Anti-Money Laundering and Anti-Terrorist Financing Regulations 2008, supervised on a sector-by-sector basis rather than by one single authority. These rules apply to defined regulated persons, including corporate service providers, banks, trust companies, investment managers, and digital asset businesses, each acting in or from the jurisdiction.

This article explains who is caught, what customer due diligence looks like in practice, how monitoring and reporting work, and what happens when a firm falls short. It is most relevant to foreign owners of Bermuda companies and their advisers, who in most cases meet these obligations through a licensed registered agent rather than carrying them directly. Policy and guidance documents referenced throughout are published by the Bermuda Monetary Authority.

The core of the regime is built from five instruments. The Proceeds of Crime Act 1997 (POCA) criminalises money laundering; the Anti-Terrorism (Financial and Other Measures) Act 2004 (ATFA) added the terrorist-financing offences; the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 set the detailed compliance duties.

Two further statutes complete the structure. The Proceeds of Crime (AML/ATF Supervision and Enforcement) Act 2008 created supervisory and enforcement powers, and the Financial Intelligence Agency Act 2007 established the body that receives suspicious activity reports. The supervision act and the Regulations both took effect on 1 January 2009.

Money laundering is criminalised at every stage under sections 43 to 45 of POCA and section 8 of ATFA, with terrorist financing covered by ATFA sections 5 to 8. The Regulations replaced an earlier 1998 instrument and widened the range of businesses caught.

The framework continues to move. Amendments arrived through the Proceeds of Crime (Miscellaneous) Act 2025, effective 20 October 2025, and the Beneficial Ownership (Consequential Amendments) Order 2025, effective 3 November 2025.

A moving target ahead of evaluation

The National Anti-Money Laundering Committee is consulting on further changes to align with updated FATF standards before the jurisdiction's 5th Round Mutual Evaluation in October 2026. Expect heightened supervisory attention in the run-up.

As a member of the Caribbean Financial Action Task Force, the regional FATF body, Bermuda is committed to the FATF 40 Recommendations, which shape the direction of every amendment described above.

Company Incorporation in Bermuda

Set up your company in Bermuda with Expanship handling registration end to end.

A useful distinction sits at the heart of the regime. The principal money-laundering offences in POCA bind everyone, but the detailed compliance machinery in the Regulations applies only to defined categories of regulated persons acting in the course of business carried on in or from the jurisdiction.

Those categories are:

  • AML/ATF Regulated Financial Institutions (RFIs)
  • Independent professionals
  • Casino operators
  • Registered dealers in high-value goods
  • Real estate brokers and agents

RFIs form the largest group and include banks, trust companies, long-term (life) insurers, collective investment scheme operators, investment managers, money service businesses, digital asset businesses, and corporate service providers. A person carrying on investment business within the meaning of section 3 of the Investment Business Act is designated an RFI by operation of law.

One feature surprises many newcomers. Reinsurers and most non-life insurers sit outside the Regulations, even though the non-life and reinsurance sectors account for roughly 80 percent of total assets in the financial sector. The carve-out reflects the lower money-laundering risk these lines of business present.

The Investment Business Act 2022 narrowed the gaps. Entities that were previously exempt or lightly touched are now required to register or hold a licence, pulling fresh AML/ATF duties along with them.

One duty reaches beyond the regulated sector entirely: the obligation to disclose a suspicion of money laundering falls on any person who forms that suspicion from information obtained through employment, trade, or business.

There is no single AML authority. Supervisory responsibility is split among sector-specific bodies, so the regulator a foreign-owned entity deals with depends on the kind of business it conducts.

AML/ATF supervisors by sector
Supervisor Sector supervised
Bermuda Monetary Authority (BMA) Regulated financial institutions, financial groups, insurers in scope
Registrar of Companies Dealers in high-value goods
Superintendent of Real Estate Real estate brokers and agents
Barristers and Accountants AML/ATF Board Regulated firms of lawyers and accountants
Casino Gaming Commission Casino operators

For most foreign-owned structures, the relevant supervisor is the BMA, because their service providers are RFIs. The BMA must monitor the persons it supervises on a risk-sensitive basis and may impose penalties where institutions fall short.

The Barristers and Accountants AML/ATF Board was designated a supervisory authority effective 10 August 2012, drawing its statutory footing from the Bermuda Bar Act 1974 and the Chartered Professional Accountants of Bermuda Act 1973.

Sitting apart from the supervisors is the Financial Intelligence Agency, an independent body established in 2007 to receive, analyse, and disseminate financial intelligence. It collects suspicious activity reports, then shares analysis with the police service and foreign intelligence counterparts where appropriate.

Policy is coordinated through the National Anti-Money Laundering Committee, established under section 49 of POCA. Its membership spans the Solicitor General, the FIA Director, the Financial Secretary, the Director of Public Prosecutions, the Commissioner of Police, the BMA's chief executive, and the Collector of Customs, among others.

Ongoing Compliance in Bermuda

Keep your Bermuda entity compliant with filings, returns, and statutory obligations.

Customer due diligence is the practical core of the regime. Regulated entities must verify who they are dealing with, understand ownership structures, and grasp the purpose behind each relationship.

The Regulations require CDD in four situations: when a business relationship begins; when a one-time transaction is carried out; when money laundering or terrorist financing is suspected; and when there is doubt about identification information previously obtained. KYC verification reaches not only the client but also beneficial owners, directors, authorised signatories, and anyone purporting to act on the client's behalf.

For a foreign owner, the most visible touchpoint is incorporation. KYC at company formation is handled by the licensed corporate service provider, which carries the due diligence obligation at the point of incorporation. The standard onboarding pack usually includes:

  • A certified copy of a valid passport or national identity card
  • Proof of residential address dated within three months, such as a utility bill or bank statement
  • A completed and signed personal declaration or KYC questionnaire

Verification can rely on physical documents, electronic data, or a combination of both. Beyond identity, the institution must hold enough information about a customer's circumstances and business to support its risk assessment and ongoing monitoring. The detail sits in Chapters 3 and 4 of the BMA General Guidance Notes, last revised June 2023.

Not every customer is treated the same way. Enhanced due diligence applies where risk is higher; simplified measures may apply where risk is demonstrably low and statutory conditions are met.

Three situations always trigger enhanced measures: non-face-to-face customers, correspondent banking relationships, and dealings with politically exposed persons. Customers connected to high-risk countries, designated from time to time by ministerial advisory, also call for enhanced scrutiny.

A politically exposed person is someone who holds or has held a high political profile or public office, a position that can carry corruption risk. That status extends to immediate family members and known associates.

When does PEP status end?

An individual stops being a PEP one year after leaving office, but a risk-based approach often justifies a longer monitoring period until the heightened risk has genuinely subsided.

Simplified due diligence is the mirror image, reserved for low-risk products and transactions under criteria set out in the Schedule to the Regulations. During on-site inspections, the BMA checks that simplified measures were applied only within those parameters and that enhanced measures reached every high-risk client. The governing detail appears in Chapter 5 and Annex IV of the June 2023 General Guidance Notes.

Bermuda Incorporation Pricing

See transparent pricing to incorporate and maintain a company in Bermuda.

Due diligence does not stop at onboarding. Throughout a relationship, transactions must be examined to confirm they remain consistent with the customer's profile and risk rating.

Particular attention is owed to complex or unusually large transactions and to patterns with no apparent economic or legal purpose; their background and intent must be investigated and documented. Senior management is expected to engage actively with money-laundering risk under Regulation 16 of the Regulations.

Policies and procedures require regular review, and certainly after legislative changes or the publication of national AML assessment results. When the BMA inspects, it expects firms to produce running figures on the number of PEP customers, the number of high-risk customers, and the volume of internal and external suspicious activity reports filed.

Records underpin every other obligation. Customer identification, transaction records, and due diligence measures must be retained for at least five years, in a form that allows transactions to be reconstructed and investigations to be supported.

The five-year clock runs from the date a relationship ends or a transaction is completed. The BMA and other competent authorities may request access to the underlying documents during regulatory reviews or investigations, so records must be retrievable on demand.

Training records matter too. Evidence that employees and personnel completed AML/ATF and sanctions training must be kept with the firm's books and available for inspection. The requirements are set out in Chapter 11 of the BMA General Guidance Notes.

When a regulated firm knows or suspects that someone is engaged in money laundering or terrorist financing, it must file a Suspicious Activity Report with the FIA. The report is due as soon as is reasonably practicable after the information comes to attention in the course of trade, profession, business, or employment.

The trigger is judgement, not value. "Knowledge" means awareness of certain facts, while "suspicion" is more subjective and falls short of firm proof; no minimum transaction amount forces a report.

Internally, staff concerns flow to the designated Reporting Officer, who decides whether an external report to the FIA is warranted. SARs are submitted through the goAML platform on the FIA's website.

Tipping off is a criminal offence

Intentionally prejudicing an investigation when you know or suspect a disclosure has been made to the FIA, or that the police are acting, is itself an offence. Treat the existence of a report as confidential.

Regulated institutions must build a governance structure around their AML duties. Appointing both a Compliance Officer and a Reporting Officer is compulsory under the Regulations.

The two roles differ in focus. The Compliance Officer ensures the required procedures and controls are in place and coordinates monitoring so compliance continues over time; the Reporting Officer handles suspicious activity reporting to the FIA. The same individual may hold both posts, and the Reporting Officer need not sit in senior management but must at least be a qualified member of staff.

Accountability runs to the top. The governing body, meaning the board, must approve the institution's AML/ATF policies, procedures, and controls under Chapter 1 of the General Guidance Notes, effective February 2023. The periodic compliance report must record the outcomes of quality assurance, audit reviews, and risk assessments.

An independent audit function is also required. It must deliver and document an objective evaluation of the framework's design and effectiveness, undertaken annually by a qualified independent third party or an appropriately qualified but independent person within the group. Staff training rounds out the controls, equipping employees to recognise and handle transactions that may relate to money laundering or terrorist financing. These duties are governed by Regulations 16 to 19.

For most foreign owners, the registered agent is where AML/KYC actually lives. Exempted companies must appoint a licensed resident representative, and this agent carries the primary obligation to verify and retain KYC records.

The arrangement has a practical consequence worth understanding. KYC documentation is collected and held by the licensed agent rather than filed directly with the BMA in routine cases, so the quality of your compliance depends heavily on the agent you choose.

Licensed corporate service providers are themselves RFIs under the Regulations. That means an agent is subject to the full suite of duties already described: customer due diligence, record-keeping, suspicious activity reporting, a compliance officer, and an annual independent audit. Licensed trust service providers carry the same obligations, including due diligence on beneficial ownership.

The BMA publishes sector-specific guidance for corporate service providers, both as Annex VI to the General Guidance Notes and as a standalone sectoral note, available through its website.

Enforcement teeth come from the supervision act, which took effect on 1 January 2009 and lets the BMA impose substantial penalties for failures under the Regulations. Civil penalty powers sit in section 20 (subsections 20A to 20I), with the full process described in Chapter 4 of that act.

Criminal exposure runs alongside the civil regime.

Selected penalties
Matter Maximum penalty
Offence on summary conviction BD$50,000 fine
Offence on conviction on indictment BD$750,000 fine, plus imprisonment
Failure to meet beneficial ownership requirements BD$250,000 fine
Unauthorised disclosure of beneficial ownership data BD$50,000 fine or two years' imprisonment

Section 33 of the supervision act creates further criminal offences, including carrying on business without the registration required under section 9. Beyond fines, the BMA can restrict business activity where a firm fails to adopt or implement its AML/ATF policies and procedures.

The direction of travel points toward firmer supervision. An increased level of on-site reviews and potentially heightened enforcement is anticipated ahead of the next mutual evaluation due to begin in 2026, and proposed 2025 amendments would name the Attorney-General's Chambers as the enforcement authority for civil recovery matters.

For a foreign owner, the practical weight of this regime rarely falls on you directly. It falls on your licensed registered agent or corporate service provider, who carries the regulated-person obligations and holds your KYC file, which makes the choice and oversight of that provider the decision that matters most.

What deserves your attention next is the run-up to the 2026 mutual evaluation, when supervisors are expected to inspect harder and enforce more readily. Confirm that your provider's controls, records, and reporting would withstand a closer look, and that your own ownership and identity documentation is current and easy to produce on request.

Expanship supports foreign owners through the AML/KYC process by handling onboarding due diligence, maintaining the KYC records a licensed agent must keep, and coordinating with supervisors and the FIA where required, then carrying that same discipline across the wider obligations of running a Bermuda entity.

  • Company incorporation and structuring for exempted entities
  • Registered agent and registered office services
  • Ongoing compliance and filing management
  • Accounting and bookkeeping support
  • Economic-substance and beneficial-ownership assistance
  • Introductions to banking partners

To discuss how these services fit your structure, contact Expanship Bermuda.

The principal money-laundering offences in POCA apply to all persons, but the detailed customer due diligence and reporting duties in the Regulations fall on defined regulated persons, such as your registered agent or corporate service provider. In most foreign-owned structures, your obligation is to supply accurate identity and ownership information so that your provider can meet its own duties.

There is no single authority; supervision is divided by sector. The Bermuda Monetary Authority oversees regulated financial institutions and corporate service providers, while bodies such as the Registrar of Companies, the Superintendent of Real Estate, and the Casino Gaming Commission supervise their respective sectors.

A licensed corporate service provider typically requires a certified copy of a valid passport or national identity card, proof of residential address dated within three months, and a signed personal declaration or KYC questionnaire. Verification can be done using physical documents, electronic data, or both.

Records of customer identification, transactions, and due diligence must be retained for at least five years, counted from the date the relationship ends or the transaction completes. They must be detailed enough to reconstruct individual transactions and support an investigation if requested.

A report is required as soon as is reasonably practicable once a regulated firm knows or suspects money laundering or terrorist financing. There is no minimum transaction amount that triggers a report; the test is knowledge or suspicion, and reports are submitted to the Financial Intelligence Agency through the goAML platform.

Civil penalties under the supervision act can be substantial, and criminal conviction carries fines of up to BD$50,000 on summary conviction or BD$750,000 on indictment, with imprisonment possible. The BMA can also restrict a firm's business activity where it fails to implement adequate AML/ATF controls.