Bermuda's digital-asset regime positions the island as a serious compliance destination for virtual asset service providers (VASPs) – businesses that exchange, transfer, or custody crypto-assets for clients. The Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer) sits at the center of that regime, and regulators at the Bermuda Monetary Authority (BMA) expect it to be implemented, documented, and audited before a firm begins operating. Failing to meet that expectation risks enforcement action, correspondent-banking termination, and regulatory suspension. This page maps the compliance program a business must build, the cross-border issues that arise when a Bermuda-licensed entity serves clients in multiple jurisdictions, and the decision points that most often stall or derail an application.
Bermuda's regulatory regime for digital-asset businesses
The Bermuda Monetary Authority (BMA) supervises digital-asset businesses under the Digital Asset Business Act (DABA) – the statutory regime that introduced licensing requirements, ongoing prudential expectations, and AML/CFT obligations for firms operating in or from Bermuda. The regime is broadly aligned with FATF Recommendation 15, which extended the same AML/CFT standards that apply to traditional financial institutions to virtual assets and the VASPs that handle them.
The BMA's supervisory posture has hardened since DABA's enactment. The authority now expects a compliance program that covers not just licensing paperwork, but a live, tested, and resource-backed operation. That includes a credentialed Money Laundering Reporting Officer (MLRO), documented policies, a transaction-monitoring system calibrated to the firm's risk appetite, and – critically – a working Travel Rule solution for cross-border transfers. Firms that file for a DABA licence without a credible compliance architecture on the table face extended review periods and, in some cases, refusal.
Bermuda also participates in the FATF mutual evaluation process. A favorable FATF standing helps Bermuda-licensed firms maintain correspondent-banking relationships, which are the first casualty when a jurisdiction lands on a gray or black list. Every compliance decision a VASP makes under DABA therefore carries a macro consequence: the island's standing is only as strong as the worst-positioned firm on its register.
For a scoped assessment of your Bermuda compliance architecture, contact OBOLUS at Map your options. The process above describes the standard path. Your facts – the entity structure, the user base, the banking counterparties, the token types handled – change the analysis materially.
What is the Travel Rule and how does it apply in Bermuda?
The Travel Rule requires a VASP to collect, verify, and transmit originator and beneficiary information alongside every qualifying virtual-asset transfer, mirroring the correspondent-banking wire-transfer rules that FATF has applied to traditional finance for decades. Under the DABA regime and its associated AML/CFT rules, Bermuda-licensed VASPs must comply with this obligation for transfers that meet the applicable threshold – and where the counterparty is another VASP, the data must travel with the transaction.
The mechanics create an immediate operational challenge. A Bermuda exchange routing a transfer to a counterparty exchange in, say, Singapore or the EU must use a compatible messaging protocol. The dominant industry protocols – including solutions that use direct API connections, the IVMS101 data standard, or dedicated Travel Rule exchange networks – all require the receiving VASP to be reachable and to have agreed on a data-sharing mechanism. Where the counterparty is in a jurisdiction that has not yet implemented the Travel Rule, or where the counterparty is unhosted (a self-custodied wallet), the compliance path diverges and requires additional risk-based steps.
Bermuda's rules do not stand alone. A VASP licensed under DABA that also holds a MiCA CASP (Crypto-Asset Service Provider) authorization in the EU – or serves EU-resident users through a cross-border arrangement – faces dual obligations. ESMA's Travel Rule implementation and the BMA's requirements must both be satisfied. Where they differ in threshold or data-field scope, the stricter obligation governs. In our cross-border practice, we regularly see firms that have addressed one regime and inadvertently left a gap in the other.
How do you build a Travel Rule compliance program for a Bermuda VASP?
Building a compliant Travel Rule program under DABA involves five interdependent layers, each of which the BMA will test at licensing and again at examination.
Layer 1: Policy and governance. The compliance program starts with a written AML/CFT policy approved at board level. The policy must define the firm's risk appetite, name the MLRO and deputy, and specify how Travel Rule data is collected, verified, stored, and transmitted. The BMA expects board minutes to evidence that senior management has approved the policy – not merely acknowledged it.
Layer 2: MLRO appointment and staffing. A credentialed MLRO must be in place before licence issuance. The BMA scrutinizes the MLRO's professional background, experience with virtual assets, and availability (part-time arrangements draw additional questions). For smaller firms, the MLRO function is sometimes outsourced to a qualified compliance officer under a managed-service arrangement. The BMA has accepted this model, but the firm must demonstrate that the MLRO has genuine oversight authority, not merely a nominal title.
Layer 3: Transaction monitoring and screening. A technology solution for real-time or near-real-time transaction monitoring is expected. The solution must be calibrated to the firm's specific risk profile – a derivatives desk serving institutional counterparties carries a different risk signature than a retail exchange. The BMA will ask for evidence that the monitoring system has been tested, that alerts are actioned, and that the escalation path to the MLRO is documented.
Layer 4: Travel Rule solution selection and integration. Selecting a Travel Rule messaging solution is a legal and technical decision that most firms underestimate. The solution must support the IVMS101 data standard, handle both VASP-to-VASP and VASP-to-unhosted-wallet scenarios, and be capable of being updated as counterparty registries evolve. In our practice, we have seen firms select a solution in isolation – without mapping how it interacts with their core banking API, their custodian, and their KYC data store. That fragmentation generates compliance gaps that surface only during the BMA's technical review.
Layer 5: Testing, record-keeping, and audit trail. The BMA expects evidence that the program works in practice, not just on paper. A pre-licensing compliance dry run – simulating a transfer across the Travel Rule solution and documenting the data chain from originator capture through transmission and receipt – is the strongest evidence a firm can present. Records must be retained for a period consistent with FATF guidance and BMA rules; destroy or fail to produce them and the firm faces a separate enforcement exposure.
Who must act as MLRO and how does governance work at a Bermuda VASP?
The MLRO is the individual legally responsible for the firm's AML/CFT program under DABA. That means receiving and evaluating internal suspicious-transaction reports, filing external disclosures with the Financial Intelligence Agency of Bermuda (FIA), and acting as the primary contact for the BMA on compliance matters. The role carries personal accountability – the MLRO cannot delegate the reporting obligation, only the day-to-day compliance work that feeds it.
The BMA expects the MLRO to hold relevant professional qualifications, to have experience with AML in a financial-services context, and to demonstrate that they understand the specific risks of virtual-asset businesses: on-chain pseudonymity, cross-chain bridges, mixer services, and the layering techniques unique to digital assets. A traditional banking compliance background helps, but without demonstrated familiarity with blockchain-specific typologies, the BMA's vetting team will push back.
Governance above the MLRO matters too. The BMA looks for a three-line-of-defense model: the business line (first line), the MLRO and compliance function (second line), and an internal or external audit function (third line). For early-stage VASPs that cannot yet sustain a full internal audit team, the third-line function can be performed by an independent external reviewer. What the BMA will not accept is a structure where the MLRO also effectively controls the audit of their own program. That structural conflict draws a targeted examination question every time.
How does Bermuda's Travel Rule obligation interact with other jurisdictions?
Bermuda-licensed VASPs rarely operate in isolation. Most serve clients across multiple jurisdictions, bank with institutions in the US, UK, or EU, and route transfers through counterparty VASPs registered under different regimes. That creates a compliance matrix that must be managed at the transaction level.
Consider a firm licensed under DABA that custody-holds assets for a family office in the UAE. The UAE operates under the VARA (Virtual Assets Regulatory Authority) regime in Dubai and the FSRA within ADGM in Abu Dhabi. VARA's AML rulebooks and the FSRA's virtual-asset framework each impose Travel Rule obligations with their own data fields and thresholds. A Bermuda custodian routing a transfer to or from a UAE-based platform must satisfy both the BMA's rules and those of the receiving jurisdiction. The most conservative standard applies at every leg.
Banking interaction adds another layer. Correspondent banks that clear USD for Bermuda-licensed VASPs increasingly require evidence of Travel Rule compliance before onboarding. In practice, a VASP without a demonstrably functional Travel Rule solution – one that can produce an audit trail on demand – will find its banking options materially narrowed. In our cross-border practice, we map the banking and compliance stack together, because a compliance gap discovered post-onboarding costs far more to remediate than it does to prevent.
Tax does not sit separately from this analysis. Bermuda has no corporate income tax, which makes it an attractive domicile. But the beneficial-ownership and economic-substance rules that apply under Bermuda law must be satisfied for the tax position to hold. Regulators in the EU and the UK scrutinize Bermuda structures under their own substance-over-form doctrines. A firm that is licensed in Bermuda but managed and controlled elsewhere faces challenges not just on tax, but on whether the Bermuda licence is genuinely operative – which the BMA itself may question if the compliance function is demonstrably offshore.
If your prior compliance structure hit a wall – a banking termination, a regulator information request, or a failed onboarding – a second read can surface the structural reason and the route back. Contact OBOLUS at Map your options.
What does the KYC framework look like for a Bermuda digital-asset business?
The KYC framework (know-your-customer due-diligence process) under DABA aligns with FATF's risk-based approach: the intensity of customer due diligence scales with the assessed risk level of the customer, the product, and the jurisdiction. Standard CDD applies to most retail customers; enhanced CDD applies to politically exposed persons, high-risk jurisdictions, and transactions above defined thresholds.
For VASPs, the KYC process must accommodate both fiat-on-ramp customers (where traditional identity documentation applies) and on-chain-only customers who may interact with the firm solely through self-custodied wallets. The latter category is particularly sensitive. A customer depositing from a self-custodied address is, by definition, the originator of a transfer to the VASP. The Travel Rule requires the VASP to collect and verify originator information for that transfer – but the customer may resist sharing a wallet address or providing a self-declaration that the wallet is beneficially owned by them.
The BMA's expectation is that the firm's policies address this scenario explicitly: what attestation is required, what happens if the customer refuses, and how the risk-based decision to proceed or exit the relationship is documented. Firms that adopt a blanket approach – either accepting all self-custodied deposits without documentation, or refusing them categorically – both run the risk of a supervisory finding. The defensible position is a documented, tiered, risk-based protocol.
Ongoing monitoring is as important as onboarding. The BMA expects periodic KYC refresh for existing customers, event-triggered re-screening (on adverse-media hits, sanctions list changes, or material transaction pattern shifts), and a process for exiting customers who no longer meet the firm's risk appetite. A well-documented exit process – including how frozen balances are handled – is a detail that many early-stage firms overlook, and one the BMA consistently tests.
A compliance gap that surfaces at banking onboarding
In a recent matter, a payments company licensed under the DABA regime approached us after a major US correspondent bank declined to proceed with account onboarding. The bank's compliance team had reviewed the firm's AML policy and identified two structural gaps: the Travel Rule solution in place did not support the IVMS101 data standard in the version the bank required, and the MLRO's documented oversight of transaction-monitoring alerts was limited to a weekly batch review rather than a real-time or same-day escalation process. We conducted a gap analysis across the full compliance program, advised on the upgrade path for the Travel Rule solution, and helped the firm restructure its MLRO oversight model. The banking relationship was subsequently re-opened. The lesson was operational: compliance documentation must be built to the standard of the most demanding counterparty the firm expects to encounter, not the minimum the regulator requires at licensing.
How do regulators audit crypto AML programs under the Bermuda regime?
BMA examinations of DABA-licensed VASPs follow a structured review process that combines document requests, management interviews, and transactional testing. The examination team will ask for the current AML/CFT policy, the most recent MLRO annual report, evidence of staff AML training, transaction-monitoring system specifications and alert logs, and a sample of customer due-diligence files at different risk tiers.
The transactional testing phase is where poorly designed programs are exposed. Examiners select a sample of transfers and trace the Travel Rule data chain from originator capture through transmission and receipt. If the data was captured but not transmitted, or if the receiving-VASP acknowledgment cannot be produced, that is a finding. If the monitoring system generated an alert that was not documented as actioned, that is a finding. Findings accumulate into a supervisory letter; a pattern of significant findings leads to a directed remediation plan with a timeline that the BMA monitors.
For firms that have received a supervisory letter or are under a remediation plan, the first task is legal analysis: which findings are purely operational (fixable with process changes) and which reflect structural deficiencies (requiring a redesign of governance, technology, or staffing). Conflating the two wastes remediation time and can give the BMA the impression that the firm does not understand the seriousness of the finding. Operators we advise in this situation consistently benefit from a structured legal and compliance review before responding to the BMA.
Which compliance structure fits your firm's profile?
Not every VASP needs the same compliance architecture. The right structure depends on the business model, the customer base, the jurisdictions served, and the firm's growth trajectory.
Profile A – Start-up exchange or broker, Bermuda domicile, retail and institutional clients, sub-threshold volumes. This firm needs a baseline DABA-compliant program: a qualified MLRO (potentially outsourced), a transaction-monitoring solution calibrated to expected volumes, and a Travel Rule solution covering the VASP-to-VASP transfer use case. The priority is getting the program documented and tested before the first BMA review. Timeline from engagement to programme-ready: a matter of weeks for a well-organized operator with clean corporate structure.
Profile B – Established custodian or exchange with multi-jurisdiction presence, institutional clients, correspondent-banking relationships. This firm needs a multi-layered program: an in-house MLRO with seniority commensurate to the risk profile, a Travel Rule solution that handles both VASP-to-VASP and unhosted-wallet transfers, dual compliance tracking across the Bermuda and any secondary regimes (MiCA, VARA, MAS, or FCA), and a third-line audit function. The cross-border dimension – particularly the banking stack – requires legal mapping before the compliance architecture is finalized.
Profile C – Firm under BMA examination or remediation, or facing correspondent-bank pressure. This firm's immediate need is a legal gap analysis and a credible response to the regulator. Remediation plans must be specific, time-bound, and realistic. Overpromising a remediation timeline that cannot be met compounds the original finding. We have seen firms damage relationships with regulators not because of the original deficiency, but because they filed a remediation plan written by someone who did not understand the operational constraints.
Profile D – Offshore fund or family office holding digital assets, not a licensed VASP. This entity may not be subject to DABA licensing, but it may still face Travel Rule obligations if it routes transfers through a Bermuda-licensed custodian. The custodian's obligations flow back to the client in the form of documentation requirements. Understanding where the firm sits in that chain is the first step.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – how we structure end-to-end compliance programs across licensing jurisdictions
- VASP business risk assessment: where the legal lines are drawn – the risk-assessment framework regulators expect before licensing
- Airdrop legal structuring in ADGM – cross-border structuring considerations for digital-asset businesses in the UAE
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, verify, and transmit identifying information about the originator and beneficiary of a qualifying virtual-asset transfer. The data must accompany the transaction and be passed to the receiving VASP. Under FATF Recommendation 15, which Bermuda's DABA regime implements, this obligation applies to transfers at or above the applicable threshold. Where a receiving VASP cannot be identified or reached, the sending VASP must apply enhanced risk-based measures before proceeding.
Who must act as MLRO for a crypto firm?
The MLRO must be an individual – not a corporate entity – with relevant professional qualifications, demonstrable experience in AML/CFT for financial services, and genuine authority within the firm. For Bermuda-licensed VASPs under DABA, the BMA vets the MLRO candidate as part of the licensing process. The MLRO is personally responsible for receiving internal suspicious-transaction reports, filing external disclosures with the Financial Intelligence Agency of Bermuda, and maintaining the firm's compliance program. Outsourced MLRO arrangements are permissible if the BMA is satisfied that genuine oversight authority rests with the individual.
How do regulators audit crypto AML programs?
The BMA examines DABA-licensed VASPs through a combination of document review, management interviews, and transactional testing. Examiners review the AML/CFT policy, MLRO annual reports, training records, and monitoring system logs. They then select a sample of transfers and trace the Travel Rule data chain end to end. Gaps in data transmission, unactioned monitoring alerts, or missing customer due-diligence documentation each constitute findings. Significant findings trigger a supervisory letter and, if a pattern emerges, a directed remediation plan with a BMA-monitored timeline.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking, and compliance stack across operating, custody, and payment layers before you commit – so gaps surface in the design phase, not in the examination. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML/CFT program design and Travel Rule implementation for VASPs across Bermuda and multi-jurisdictional licensing stacks.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.