EST · MMXXVI
Home/Jurisdictions/Bermuda/VASP business risk assessment in Bermuda
Compliance, AML & Travel Rule

VASP business risk assessment in Bermuda

Vasp business risk assessment in Bermuda. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A virtual asset service provider (VASP) expanding into or through Bermuda faces a regulatory environment that is more demanding than its offshore reputation suggests. The Bermuda Monetary Authority administers a purpose-built digital-asset regime that requires a formal business risk assessment before a VASP can operate with confidence – and that assessment touches every layer of the business, from AML program design to transaction monitoring, cross-border data flows and banking access. Operators who treat a VASP registration as a checkbox exercise, rather than a live compliance instrument, discover the problem only when a correspondent bank demands evidence of a functioning program or a regulatory examination surfaces gaps. This page sets out the regulated basis for the risk assessment, the practical process, the cross-border dimensions that Bermuda-registered VASPs routinely encounter, and the decision points that determine whether the structure is defensible.

What is the regulated basis for VASP compliance in Bermuda?

Bermuda's digital-asset regime is administered by the Bermuda Monetary Authority (BMA) under the Digital Asset Business Act and associated AML/ATF regulations. The regime is not a light-touch registration: it requires a Class F licence (full digital asset business) or a Class M licence (modified, for smaller operators), each carrying distinct conduct and prudential expectations. The BMA has statutory authority to examine a licensee's AML/CFT posture at any time, and it reviews the adequacy of a firm's enterprise-wide risk assessment as a primary indicator of supervisory compliance. Operating without a valid BMA licence while conducting digital asset business activities in or from Bermuda exposes the operator to enforcement, including civil monetary penalties and licence suspension or revocation.

The regulatory architecture aligns closely with FATF Recommendation 15, which requires jurisdictions to apply risk-based AML/CFT measures to VASPs. Bermuda has implemented that standard through its domestic regime, meaning a Bermuda VASP must maintain a written enterprise risk assessment, appoint a qualified Money Laundering Reporting Officer (MLRO), run a transaction monitoring system calibrated to the firm's risk profile, and apply the Travel Rule (the obligation to pass originator and beneficiary data with each qualifying transfer). The BMA expects these elements to be contemporaneous and documented, not reconstructed for an inspection.

In our practice, we see operators arrive in Bermuda with a generic AML policy copied from another jurisdiction. That policy fails on three points: it does not reflect Bermuda's specific customer-risk indicators, it does not address the BMA's expectations on Travel Rule data exchange, and it contains no evidence of senior-management sign-off on a jurisdictional risk assessment. All three are BMA examination priorities.

For a scoped assessment of your AML program's alignment with Bermuda's BMA requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity's activity set, the user base geography, and the banking arrangement – change the analysis materially.

What does a VASP business risk assessment cover in Bermuda?

A VASP business risk assessment in Bermuda is a structured, written analysis of every material risk the business generates or is exposed to, mapped against the controls in place to mitigate those risks. It is not a theoretical document: the BMA treats it as a live compliance instrument and benchmarks the firm's monitoring and reporting activity against it. The assessment must cover, at minimum, the customer risk universe, the product and service risk profile, the geographic risk of the firm's counterparty base, the delivery-channel risk of its transaction architecture, and the residual risk after controls are applied.

Customer risk is typically the most complex layer for a digital-asset firm. The assessment must differentiate between retail and institutional customers, between custodial and non-custodial wallet holders, and between customers whose source-of-funds documentation is verifiable through traditional means and those operating in higher-risk environments. For an exchange or custodian, this means maintaining tiered KYC (know-your-customer) thresholds calibrated to transaction volume and customer type, with enhanced due diligence procedures triggered automatically at defined risk indicators.

Product and service risk requires the operator to characterize each service it offers – spot trading, OTC brokerage, staking, lending, custody – and assign a residual risk rating based on the anonymity features of the assets involved, the reversibility of transactions, and the speed at which value can be transferred. The BMA expects this matrix to be updated whenever the firm adds a product line or expands into a new asset class. Token classification matters here: a firm trading security tokens (tokens conferring equity or debt rights) faces a different regulatory interaction than one trading payment tokens, and the risk assessment must reflect that distinction.

Geographic risk analysis for a Bermuda VASP is inherently cross-border. Most Bermuda-licensed digital-asset businesses serve clients across multiple time zones and jurisdictions. The risk assessment must therefore map the FATF status of the countries from which customers originate, flag any enhanced-risk jurisdictions listed on the BMA's internal watchlists, and document the controls applied to business from those territories. This is the point where a nominally offshore structure collides with reality: a Bermuda-licensed VASP serving customers in higher-risk jurisdictions carries a materially higher enterprise risk rating than one serving a narrow institutional base in well-regulated markets.

Who must act as MLRO for a Bermuda VASP, and what does the role require?

The BMA requires every licensed digital-asset business to designate a qualified individual as MLRO, and that designation must be approved by the regulator before the person takes up the function. The MLRO is the statutory pivot of the AML/CFT program: they receive internal suspicious activity reports, make the assessment of whether to file a Suspicious Activity Report (SAR) with the Financial Intelligence Agency (FIA) of Bermuda, and are the primary point of contact for law-enforcement inquiries and BMA supervisory engagements.

The MLRO must have sufficient seniority, independence and expertise to carry the function credibly. The BMA expects the MLRO to understand the specific money-laundering typologies relevant to digital assets – chain-hopping, peel-chain structuring, mixing and tumbling, cross-chain bridges as obfuscation tools – and to be able to translate transaction-monitoring alerts into defensible SAR decisions. A compliance officer who understands traditional financial services but lacks direct exposure to on-chain transaction analysis is unlikely to satisfy the BMA on examination.

For smaller operators or those in the early stages of their Bermuda licensing process, the BMA has accepted a shared or part-time MLRO arrangement in limited circumstances, subject to a clear demonstration that the individual has sufficient time to discharge the function and that the arrangement does not create conflicts. We advise clients to treat this as a narrow carve-out, not a default model: the cost of an under-resourced MLRO function manifests as enforcement risk, not just regulatory friction.

How does the Travel Rule apply to Bermuda VASPs in practice?

The Travel Rule – the obligation to collect, verify and transmit originator and beneficiary data with qualifying virtual-asset transfers – applies to Bermuda-licensed VASPs under the BMA's AML/ATF framework, consistent with FATF Recommendation 16. The practical challenge is not understanding the obligation; it is implementing a data-exchange mechanism that works across counterparties who may be operating under different Travel Rule protocols in different jurisdictions.

Bermuda sits in a cross-border environment where its VASPs routinely interact with counterparties regulated under MiCA in the European Union, under the Payment Services Act regime of MAS in Singapore, or under FCA registration in the United Kingdom. Each of those regimes carries a Travel Rule data threshold and protocol expectation that may differ from Bermuda's domestic implementation. A Bermuda VASP that sends a transfer to a MiCA-regulated counterparty must therefore satisfy both the BMA's outbound data requirements and the receiving CASP's inbound data expectations – and failure to achieve that creates a compliance gap at both ends.

In our cross-border practice, we regularly advise VASPs on selecting and implementing a Travel Rule solution that is protocol-agnostic – meaning it can communicate with IVMS101-compliant counterparties regardless of the specific messaging overlay they use. The risk assessment must document the firm's Travel Rule solution architecture, the counterparty onboarding process (including what happens when the counterparty VASP cannot be identified as a regulated entity), and the controls applied to transfers involving unhosted wallets.

Unhosted wallet transactions represent a distinct Travel Rule challenge. The BMA, consistent with FATF guidance, expects VASPs to apply risk-based controls to transfers from or to unhosted wallets, including measures to identify the beneficial owner of the wallet where the transfer exceeds a defined risk threshold. The risk assessment must document that decision logic explicitly.

What does an adequate transaction monitoring program look like under BMA supervision?

Transaction monitoring under the BMA regime is a rule-and-behavior-based surveillance obligation, not merely a sanctions-screening function. The VASP must operate a system capable of detecting structuring patterns, unusual velocity, counterparty concentration risk, and the use of privacy-enhancing techniques that obscure the on-chain origin or destination of funds. The system must generate alerts, and those alerts must be reviewed, escalated where necessary, and documented in a way that is audit-ready.

The BMA is increasingly sophisticated in its examination of transaction monitoring programs. Examiners look for evidence that alert thresholds are calibrated to the firm's specific risk profile rather than set at generic industry defaults. A firm that has never tuned its monitoring parameters since go-live, and whose alert volume has remained constant despite substantial growth in transaction activity, will attract scrutiny. The BMA expects the VASP to demonstrate a feedback loop: alert review outcomes should inform threshold recalibration, and that process should be documented and signed off by the MLRO and senior management.

Integration with a forensic analytics platform – using on-chain intelligence tools to score wallet addresses and cluster transaction behavior – is now effectively a market standard for regulated VASPs in the leading hubs, and Bermuda is no exception. The risk assessment should identify which tool the firm uses, how its risk-score outputs are mapped to the firm's internal risk tiers, and what action is triggered at each tier. The BMA will ask these questions on examination; the answers must be in writing before the examination begins.

In a recent compliance review matter, a mid-market exchange had deployed a transaction monitoring system but had not integrated its on-chain analytics output into the alert-review workflow. The two systems operated in parallel, creating a documentary gap that regulators flagged during a thematic review. We assisted in restructuring the workflow and documenting the integration, bringing the program into alignment with the regulator's expectations before a formal finding was issued.

How do banking access and tax interact with a Bermuda VASP's risk profile?

Bermuda's banking environment for digital-asset businesses is tighter than the licensing regime's international profile implies. Most Bermuda-incorporated banks apply enhanced due diligence to VASP clients as a matter of correspondent-bank risk management, and some decline the sector entirely. A VASP that secures a BMA licence but cannot open a fiat settlement account has a compliance-paper structure that cannot operate commercially. The business risk assessment must therefore address banking-access risk as an enterprise risk category, not an afterthought.

The practical approach we advise is to run the banking access process in parallel with the licensing application, not sequentially. This requires presenting the bank with a completed or near-completed AML/CFT program, including the risk assessment, the MLRO designation, and evidence of a functioning transaction monitoring capability. Banks making an enhanced due diligence decision on a VASP client are evaluating the quality of the firm's compliance infrastructure as much as its business model. A well-documented risk assessment is a direct input into that decision.

Tax treatment in Bermuda is a structural advantage: there is no corporate income tax, no capital gains tax, and no withholding tax on dividends or interest. These features make Bermuda an attractive domicile for holding structures and treasury functions within a digital-asset group. However, the absence of local tax liability does not eliminate the tax complexity for a Bermuda VASP with operations, customers or management in other jurisdictions. Controlled foreign corporation rules, permanent establishment risk, and the OECD's Pillar Two framework all apply to the group structure, and those obligations must be mapped before the Bermuda entity is committed to a structural role it cannot sustain.

What are the most common failures in VASP risk assessments that the BMA identifies?

The BMA's supervisory record and industry guidance point to a consistent set of deficiencies in VASP risk assessment programs. First is the absence of a genuine enterprise-wide scope: firms produce a customer-due-diligence policy and call it a risk assessment. The BMA expects a document that covers all five risk categories (customer, product, geography, delivery channel, residual) and that maps each risk to a named control and an accountable owner.

Second is the failure to update the assessment after material changes to the business. A risk assessment signed off at licence application that has not been revised after the firm added a staking product, onboarded a new institutional client segment, or expanded its geographic user base is not current – and the BMA will note the discrepancy between the assessment and the live business in any examination.

Third is the disconnect between the risk assessment and the transaction monitoring configuration. If the assessment identifies high-risk customer types or asset classes, the monitoring thresholds must reflect that: a firm that rates privacy coins as elevated risk but has no specific monitoring rule for privacy-coin transactions has documented a gap rather than a control.

A common assumption among operators entering Bermuda is that a strong licensing framework in another jurisdiction transfers credibly to the BMA. It does not work that way. The BMA conducts its own assessment of each licensee's compliance program and expects documentation produced for Bermuda, not a copy of a VARA or MiCA submission with the jurisdiction name changed. We regularly see firms spend months in a BMA licensing process only to be asked to revise their AML program fundamentally. Front-loading the program quality saves that time.

If a prior BMA application stalled or a compliance gap has been flagged, write to OBOLUS at info@oboluslaw.com. A second read of the program can surface the structural reason and the route back to a defensible position.

Which operator profile is Bermuda best suited for, and when should the structure be re-examined?

Bermuda works best for a defined set of operator profiles. An institutional digital-asset business – a custodian, an OTC brokerage serving professional counterparties, or a fund-linked trading entity – finds in Bermuda a credible regulatory imprimatur, a sophisticated legal system rooted in English common law, and a tax-neutral domicile. The BMA licence signals to institutional counterparties and banks that the operator has submitted to a genuine compliance examination, which has commercial value beyond the regulatory permission itself.

For a retail-facing exchange with a broad consumer base, Bermuda is a less natural fit. The BMA's compliance expectations are calibrated for institutional or semi-institutional operators; the licensing process is not designed for high-volume retail onboarding at scale. An operator with significant retail ambitions will often find that a MiCA CASP authorisation in an EU member state, or a MAS Digital Payment Token licence in Singapore, better aligns with the distribution model, and that Bermuda serves better as the holding or treasury layer rather than the regulated operating entity.

A two-entity structure – Bermuda holding company plus an operating-jurisdiction VASP licence – is a structure we regularly advise on. In that model, the business risk assessment function exists at both levels: the Bermuda entity for the BMA, and the operating entity for its local regulator. Ensuring consistency between the two assessments, and a clear delineation of which entity carries which risk, is a structural task that should be addressed before the first application is filed.

The trigger to re-examine the structure is usually one of four events: a material change in the user-base geography, a new product line that changes the risk profile, a banking-access disruption, or a regulatory inquiry. Any of these events should prompt a fresh risk assessment cycle and a review of whether the jurisdictional structure still serves the business's operating and compliance objectives.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect verified originator and beneficiary information – including names, account identifiers and, in most implementations, address data – and transmit that information to the receiving VASP with each qualifying virtual-asset transfer. The data threshold at which the obligation attaches varies by jurisdiction. A Bermuda VASP must satisfy both the BMA's outbound requirements and the inbound requirements of the receiving institution's home regulator, which may differ in scope and format.

Who must act as MLRO for a crypto firm?

The MLRO must be an individual with sufficient seniority, independence and expertise to receive and assess internal suspicious-activity reports, file SARs with the relevant financial intelligence unit where required, and act as the primary regulatory contact for AML examinations. For a Bermuda-licensed digital-asset business, the BMA must approve the MLRO designation before the person takes up the function. The role cannot be performed by someone without direct exposure to digital-asset transaction typologies and on-chain monitoring practice.

How do regulators audit crypto AML programs?

Regulators typically assess the written enterprise risk assessment, the adequacy of the KYC and transaction monitoring systems, alert-review documentation, SAR filing history, MLRO governance records and staff training logs. For a Bermuda-licensed VASP, the BMA can conduct on-site or desk-based examinations at any time. Examiners increasingly test whether monitoring thresholds are calibrated to the firm's live risk profile and whether the documented controls match actual operational practice – not simply whether a policy document exists.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before clients commit – ensuring that the structure is defensible from the risk assessment through to the banking relationship. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, VASP risk assessments and cross-border compliance architecture for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours