Listen to this article
0:00 / 0:00

Key Takeaways

  • Both financial businesses and designated non-financial businesses and professions can fall within scope of AML/KYC obligations in Turks and Caicos.
  • Customer due diligence, enhanced due diligence for politically exposed persons, and ongoing monitoring form the core of a covered business's compliance duties.
  • Record-keeping and suspicious activity reporting to the Financial Intelligence Agency are mandatory, with the registered agent playing a defined role for foreign-owned companies.
  • Non-compliance carries penalties and enforcement action overseen by the Financial Services Commission, making documented internal controls important for non-resident owners.

Anti-money laundering and know-your-customer rules apply in Turks and Caicos, and they bind a defined set of businesses rather than the general population. The regime sits on the Proceeds of Crime Ordinance 2007, its subsidiary regulations, and a binding Code, all supervised by the Financial Services Commission. If you own or advise a licensed entity, a company service provider, or a designated non-financial business there, these obligations reach you directly.

For most foreign owners, the practical point is this: your registered agent or service provider carries the heaviest AML/KYC load, but the underlying entity still feels the effect through due diligence requests, document demands, and record-keeping. This article explains who is covered, what controls and customer checks are required, how suspicious activity is reported, and what happens when rules are breached. The Commission's framework page is the starting reference for the law that governs all of this.

It is most relevant to anyone holding a regulated licence, operating as a company manager or trust company, or running a business classed as a designated non-financial profession.

The legislative base dates from 2007, when the Proceeds of Crime Ordinance (POCO) replaced earlier drug-trafficking and proceeds legislation and consolidated money-laundering offences into one statute. Those offences sit at sections 115 to 124 and follow an "all serious crimes" approach to predicate offences.

Three instruments give the Ordinance its working detail: the Anti-Money Laundering and Prevention of Terrorist Financing Regulations 2010, the matching Code of 2011, and the Non-Profit Organisations Regulations 2014. Each has been amended more than once.

The Code carries real weight. Issued by the Anti-Money Laundering Committee under section 111(1) of POCO, it has the same legal force as if its provisions sat inside the Ordinance or the Regulations themselves.

Terrorist financing is handled separately. POCO does not cover it; that ground is occupied principally by UK Orders extended to the territory, including the Terrorism (United Nations Measures) (Overseas Territories) Order 2001 and the Terrorist Asset-Freezing Etc. Act 2010 (Overseas Territories) Order 2011.

As a member of the Caribbean Financial Action Task Force, a regional FATF body, the jurisdiction has committed to the FATF standard for preventing money laundering and combating the financing of terrorism and proliferation. The combined effect is a risk-based regime that applies to both natural and legal persons, criminally and civilly.

Company Incorporation in Turks and Caicos

Set up your company in Turks and Caicos with Expanship handling registration end to end.

Two bodies sit at the centre of day-to-day AML work, and they do different jobs. The Financial Services Commission supervises; the Financial Intelligence Agency receives reports.

The Commission's supervisory mandate comes from section 4(1)(d) of the Financial Services Commission Ordinance 2007 and is reinforced by POCO, which names it the supervisory authority for regulated financial business at section 148F(1). Through Regulation 23 of the 2010 Regulations, it is also the sole supervisor of designated non-financial businesses and professions, and it supervises the non-profit sector under the 2014 Regulations.

As an independent statutory regulator, the Commission conducts on-site and off-site examinations to test compliance and can impose sanctions where it finds failures. Its functions as supervisory authority, including the duty to enforce, are set out at section 163(1) of POCO.

The Financial Intelligence Agency, established under the Financial Intelligence Agency Ordinance, is the Reporting Authority designated by section 109(1) of POCO. All suspicious activity reports go to it.

The Agency acts as the territory's Financial Intelligence Unit and belongs to the Egmont Group of more than 150 such units worldwide. It receives, stores, analyses, and disseminates intelligence on suspected money laundering, terrorist financing, and proliferation financing.

National policy is coordinated through the Anti-Money Laundering Committee, whose functions appear at section 116 of POCO. Chaired by the Attorney General with the Commission's Managing Director as deputy, it draws members from the Attorney General's Chambers, the Commission, the Agency, the police, the Director of Public Prosecutions, Customs, the Integrity Commission, and the Gaming Control Commission.

Where to direct filings

Supervision and licensing queries go to the Financial Services Commission at www.tcifsc.tc; suspicious activity reports go to the Financial Intelligence Agency at www.fia.tc. The two are not interchangeable.

Coverage is broad. Financial businesses, the designated non-financial professions, and non-profit organisations all fall within the AML/CFT requirements, with the list of financial businesses set out in Schedule 2 of the Regulations.

The Commission licenses and supervises a wide spread of activity: banks, money transmitters, mutual funds and fund administrators, investment dealers, trust companies, insurers and insurance agents, company service providers, and international business companies. Designated non-financial businesses and professions cover lawyers, accountants, real estate agents, and dealers in high-value goods.

These professions were brought into scope when POCO and the 2010 Regulations were amended in response to FATF recommendations. A 2013 Commission notice extended registration to independent legal professionals, high-value item dealers, and accounting or auditing service providers.

If your business is a designated non-financial firm, registration with the Commission has concrete steps. Every owner holding 10 percent or more, each director or equivalent, each manager, and the appointed compliance and reporting officers must submit a Personal Declaration Questionnaire.

Registration is not a one-off. It must be renewed every three years from the date of first registration, material changes must be notified in writing within 30 days, and an Update Form is due each year.

Designated non-financial business registration: fees and dates
Item Detail
Business name registration fee USD 50 (on initial registration)
DNFBP registration fee USD 150 (on initial registration)
Registration renewal Every three years from first registration
Notify material changes Within 30 days, in writing
Annual Update Form Due 31 January each year

Ongoing Compliance in Turks and Caicos

Keep your Turks and Caicos entity compliant with filings, returns, and statutory obligations.

The regime asks businesses to think before they tick boxes. A documented risk assessment of the client base and business activities is the foundation, and it must be kept under regular review rather than filed and forgotten.

That assessment has to address risks arising from customers, the products and services offered, the entity's structure, its delivery channels, and its geographic connections. Risk drives the depth of every other control.

For financial businesses, two appointments are mandatory. A Money Laundering Compliance Officer runs the compliance programme, and a Money Laundering Reporting Officer receives internal reports, decides whether they warrant escalation, and files with the Agency.

Both appointments need the Commission's approval under Regulations 21 and 22. The roles may be outsourced with prior approval, but accountability never leaves the most senior person in the organisation.

Beyond the two officers, the Commission's requirements set out a working compliance system:

  • Written compliance policies and procedures, kept current and approved by a senior officer
  • An ongoing training programme for staff, agents, and authorised persons, supported by a documented training plan
  • A documented plan to test the effectiveness of the compliance programme, with that review carried out at least every two years

Non-profit organisations are treated differently and are not subject to the MLCO and MLRO appointment rules, though they carry their own due diligence and record duties.

Customer due diligence is the everyday face of the regime. The Regulations require identification and verification measures before a business relationship begins or a transaction is carried out, along with information on the purpose and nature of that dealing.

Regulation 4 puts this in plain terms: a person carrying on relevant business must not form a relationship or handle a one-off transaction unless the required procedures are in force and actually followed. A failure on identification is both a breach of Regulation 4 and an offence under the Regulations.

For legal entities, due diligence must reach through to beneficial ownership. The 10 percent threshold appears clearly for disclosure of ownership in a designated non-financial firm's own registration; the precise beneficial-ownership threshold for client due diligence under the Regulations should be confirmed against the full regulatory text, which is not reproduced in public summaries.

The Code deliberately leaves room for judgement. Its aim is a proportionate, risk-based approach rather than a mechanical one, so the depth of checks scales with the risk a customer presents.

One practical caution for foreign owners: specific monetary triggers for occasional transactions, such as the figures used in FATF guidance, were not identified in public territory-specific sources. Verify any threshold directly in the AML/PTF Regulations 2010 as amended before relying on it.

Turks and Caicos Incorporation Pricing

See transparent pricing to incorporate and maintain a company in Turks and Caicos.

Higher-risk relationships call for more. The Regulations contain enhanced due diligence measures and dedicated provisions for politically exposed persons, the international standard the territory has committed to under FATF Recommendation 12, covering both foreign and domestic figures.

Enhanced measures typically mean senior management sign-off, documentation of source of wealth, and closer ongoing monitoring. The exact section numbers for these requirements are not reproduced in public sources, so the full text of the Regulations and the Code should be read directly where precise wording matters.

A CFATF evaluation has flagged that supervision of certain sectors, including legal professionals, dealers in precious metals, casinos, and real estate, needs stronger risk-based mitigation. Whether a strict "once a PEP, always a PEP" rule applies, or some de-listing period, is not settled in public material; most FATF-aligned regimes apply continued, risk-based enhanced checks for a period after a person leaves office.

Due diligence does not end at onboarding. The Regulations require ongoing monitoring of business relationships, tied back to the documented risk assessment that the regime treats as a living process.

Monitoring sits alongside the training programme and the two-year effectiveness review already required of financial businesses. The Agency supports this with annual outreach and awareness sessions, reminding reporting entities of their duty to report all suspicious and attempted transactions.

Refresh triggers, such as a material change in a customer's circumstances or doubt about earlier identification, are dealt with in the Regulations and the Code. Precise section references for those triggers are not available in public summaries and should be checked in the source text.

Records are the proof that controls worked. Financial businesses must keep identity records and records of business relationships for at least five years, with the categories of records specified at Regulation 18(2) and the manner of keeping set out across Regulation 18.

The five-year clock runs from the end of the relationship or the date of the transaction, following the general FATF standard; the exact trigger point should be confirmed against Regulation 18 itself. Public sources do not state whether records must be hard copy, electronic, or either, nor where they may be held, so confirm these practical points before designing a storage system.

Non-profit organisations carry a distinct set of record duties. Their administrative records must include due diligence on all controllers, the governing document, a register of controllers with appointment and departure details, corporate records where relevant, and records of fund distributions and beneficiaries, including the reasons beneficiaries were chosen.

When suspicion arises, the duty to report is firm. A person with knowledge or suspicion of money laundering or terrorist financing must file a suspicious activity report with the Agency, which section 109(1) of POCO names as the Reporting Authority.

In practice the report moves through the Money Laundering Reporting Officer, who channels disclosures to the Reporting Authority through the Financial Crimes Unit. All financial institutions, designated non-financial businesses, and non-profits must report both attempted and completed suspicious transactions.

POCO protects those who report in good faith from civil liability that might otherwise follow disclosure. It also makes failure to report an offence, and it prohibits tipping off the subject of a report.

Two practical gaps are worth flagging. No standard SAR form name or dedicated electronic filing portal was identified in public sources, and no fixed filing deadline after suspicion arises was confirmed; the Agency at www.fia.tc is the contact point, and the precise timeframe should be verified with it or in POCO.

For a foreign-owned entity, the registered agent is usually where AML obligations land in practice. Company management and trust businesses are licensed separately under the Company Management (Licensing) Ordinance and The Trusts Ordinance, and they are classed as financial businesses under Schedule 2.

That classification matters. It means a company manager's AML/KYC duties are those of a full regulated financial business, not the lighter designated non-financial standard, so the manager must appoint an MLRO and MLCO and run the full control framework.

A licensed agent acting as intermediary must apply complete customer due diligence to the beneficial owners of every entity it manages or administers. Regulation 4 prevents it from forming a relationship at all unless those identification procedures are in force and followed.

This is why your service provider will press for identity documents and ownership detail before and during the engagement. The agent's wider role as a channel for beneficial-ownership information to the Commission's registry is governed by separate guidance, which advisers should consult directly for the precise mechanics.

The consequences run from criminal conviction to licence loss, and they apply to both individuals and entities. The money-laundering offences carry the heaviest sanctions.

Criminal money-laundering penalties under POCO
Section Conduct Maximum penalty
117 Concealing, disguising, converting, transferring, or removing criminal property Up to 14 years' imprisonment and/or an unlimited fine
118 Entering into or being concerned in an arrangement facilitating acquisition of criminal property Up to 14 years' imprisonment and/or an unlimited fine
119 Acquisition, use, or possession of criminal property Up to 14 years' imprisonment and/or an unlimited fine

Failure to report suspicion to the Agency is itself an offence under POCO. So is a breach of the identification provisions, which engages Regulation 4 and the offence provisions of the Regulations.

On the regulatory side, the Commission can act directly. The Code is fully enforceable against regulated persons, allowing the Commission to revoke licences or take other enforcement action following its examinations, with the duty to enforce grounded in section 163(1) of POCO.

Asset recovery sits with two offices. Post-conviction confiscation under Part II of POCO is run by the Director of Public Prosecutions, while the Attorney General, as Civil Recovery Authority under Part III, can pursue proceeds of unlawful conduct without a conviction through the Supreme Court on the civil standard.

One figure is genuinely absent from public material: the schedule of administrative fines the Commission may impose short of prosecution. Confirm those amounts with the Commission's enforcement schedule rather than assuming a number.

The honest assessment for a foreign owner is that AML/KYC here is real and enforced, but the burden falls unevenly. A passive holding company carries little hands-on obligation, while a licensed financial business or company manager runs a full compliance machine of appointed officers, documented risk assessments, training, and five-year records.

Decide which side of that line your entity sits on before anything else, because it determines whether you manage compliance yourself or rely on a regulated provider to carry it. Several precise points, including beneficial-ownership thresholds, SAR deadlines, and administrative fine levels, are not settled in public sources and warrant direct confirmation against the Regulations.

Expanship supports foreign owners on AML/KYC by handling due diligence documentation, helping appoint and register compliance and reporting officers where required, and keeping the underlying entity ready for the checks its service provider and the regulator will run. The same team manages the broader compliance picture for a foreign-owned company in the territory.

  • Company formation and structuring for non-resident owners
  • Registered agent and registered office services
  • Ongoing compliance management and statutory filings
  • Accounting and bookkeeping support
  • Economic-substance and beneficial-ownership assistance
  • Introductions to banking partners

To discuss your obligations and the right level of support, contact Expanship Turks and Caicos.

The full AML control framework binds licensed financial businesses, company managers, and designated non-financial professions rather than every entity. A passive company still experiences the regime indirectly, because its registered agent must apply customer due diligence to the beneficial owners under Regulation 4 before and during the engagement.

The Financial Services Commission is the supervisory authority for both regulated financial business and designated non-financial businesses, conducting examinations and imposing sanctions. Suspicious activity reports go separately to the Financial Intelligence Agency, named as the Reporting Authority under section 109(1) of POCO.

Financial businesses must retain identity and business-relationship records for at least five years, with the specific categories set out at Regulation 18(2). The period generally runs from the end of the relationship or the transaction date, though the exact trigger should be confirmed against Regulation 18.

Initial registration carries a USD 50 business name registration fee and a USD 150 designated non-financial business registration fee. Registration must then be renewed every three years, with an Update Form due by 31 January each year and material changes notified within 30 days.

The core offences at sections 117 to 119 of POCO each carry up to 14 years' imprisonment and an unlimited fine, applying to both natural and legal persons. Separately, failing to report suspicion to the Agency is an offence, and the Commission can revoke licences or take other enforcement action against regulated persons.

Yes. Company management and trust businesses are classed as financial businesses under Schedule 2, so they carry the full regulated standard, including appointed MLRO and MLCO roles, rather than the lighter designated non-financial obligations.