What Actually Binds a Registered and Supervised Person in Jersey
06/08/2026
Below is a layer-by-layer article and guide about Jersey's financial services legal and regulatory hierarchy. Before you get to the article, I have added some highlights to encourage you to read to the end.
Introduction to the article: what actually binds a Registered and Supervised Person in Jersey (see below)
- Ask most compliance practitioners in Jersey what they “must” comply with, and the answer usually collapses everything the JFSC publishes into a single undifferentiated category: “the regulator's requirements.”
- In practice, a registered and supervised person* operates under several distinct instruments: primary law, Codes of Practice issued under two different statutory bases, Policy Statements that acquire Code-level force by incorporation, scope-determining Guidelines, formally non-mandatory Guidance Notes, thematic examination feedback, informal industry updates, and Dear CEO letters.
- Each carries a different legal foundation and a different practical consequence for getting it wrong.
- Conflating these layers is not an academic error. It produces defence submissions, board reports and JFSC correspondence that either overstate what is strictly mandatory or, more dangerously, understate the evidential weight a firm needs when it departs from published expectations.
- The moments that actually matter- an examination, an enforcement conversation, an Article 21B penalty assessment- rarely turn on whether a document was formally binding. They turn on whether the board can demonstrate it identified the relevant expectation, assessed its significance, and acted appropriately.
- A board that can only say “it wasn't mandatory” has answered a question nobody was asking.
This article does four things.
- Maps the hierarchy as it actually stands today, across the whole regulatory perimeter rather than the narrow AML/CFT slice that dominates most commentary.
- Flags the points at which the JFSC itself has said practitioners are getting the status of documents wrong.
- Examines a 2026 legislative change that has tightened one specific link in the chain, creating what this article labels a “two-tier Code risk” that did not exist before 30 June 2026. That label is this article's own shorthand for the practical effect described below, not a term used by the JFSC itself; see the note on terminology near the end of this article.
- Shows how material that is formally non-mandatory (thematic feedback, Guidance Notes, “quick wins,” Dear CEO letters) nevertheless generates real supervisory and enforcement consequences.
The article highlights the hidden risks most compliance teams don't know about.
A few findings below will surprise even experienced practitioners. Read on for the detail behind each one.
- Since 30 June 2026, getting an AML/CFT/CPF Code point wrong on the MLCO risk-based exemption touches a duty defined directly in primary legislation, but getting a TCB, FSB, IB or AIF Code point wrong on the same underlying issue does not. “Code” no longer means one consistent thing across a firm's obligations (see Layer 2 and “The 2026 Tightening”).
- The JFSC has confirmed, in writing, that Handbook guidance is “not mandatory.” It has also confirmed, in the same enforcement framework, that ignoring that same guidance is an aggravating factor when a fine is calculated. Both statements are true at once (see Layer 4 and “Enforcement Teeth”).
- A “quick wins” industry update has zero legal status, not a Code, not even a Guidance Note. Yet, it may be the single most operationally useful thing the JFSC publishes, because it's a live readout of what examiners are finding on file review right now (see Layer 6).
- Thematic examination feedback is addressed to the whole industry, not just the firms examined. A firm that was never visited is still expected to read it, self-assess, and act; and acting on it can walk that firm straight into a mandatory Code-level notification it didn't know it owed (see Layer 5).
- Since 2022, the JFSC's power to fine reaches individuals, not just firms, for a breach of any JFSC Code, and it does not distinguish the “stronger” AML/CFT Codes and the “softer” sector Codes when doing so. This is a separate mechanism from the two-tier Code risk above: it doesn't contradict it; it sits alongside it (see “Enforcement Teeth”).
- A Dear CEO letter creates no new legal obligation whatsoever. Still, it is usually the earliest and clearest signal of where enforcement is heading, often years ahead of any change to the Codes or Handbook themselves (see Layer 7).
- Natural-person penalty caps are fixed regardless of firm size. An MLCO or MLRO at a small trust company faces the same maximum personal exposure as one at a systemically significant bank (see “How the JFSC decides whether to fine, and how much”).
The article highlights personal exposure: what individuals should actually worry about
The points above apply to firms. These apply to the people inside them, and several are easy to miss.
- Liability doesn't end when you leave the role. Article 21A reaches “any person who performs or performed” a senior management function: a former MLCO, MLRO, or designated senior manager can still be pursued for a contravention that occurred while they held the role, even after they've moved on or left the firm entirely.
- You don't need to have caused the breach yourself. The same Article extends to anyone whose consent, connivance, or neglect contributed to a contravention, or who “aided, abetted, counselled or procured” it. Enabling someone else's failure is enough to be personally in scope.
- “Senior management function” reaches well below board level. The JFSC's four categories catch compliance and risk managers directly. Category 3 specifically catches anyone performing a single defined duty the MLO or Codes require senior management to perform, for example, approving continuation of a PEP relationship or approving a new correspondent banking relationship. A person with no senior title can fall into personal scope for one decision.
- Personal penalty caps don't scale down for smaller firms. The £10,000 / £200,000 / £300,000 / £400,000 maxima apply regardless of firm size: an MLCO at a small trust company faces the same ceiling as one at a major bank.
- Reputational fallout is built into the penalty calculation, not a side effect of it. The JFSC's own registered-persons methodology explicitly assumes a contravention will become public knowledge when scoring its “seriousness”: through a public statement issued alongside the penalty in almost every case, settlement or not. This is confirmed practice, not just methodology text: the JFSC's own “Our Approach to Enforcement” states that a public statement setting out the reasons is issued whenever a civil financial penalty is imposed.
- A finding of lack of integrity doesn't require a finding of dishonesty, and it can end a career anyway. Under the fit-and-proper test, the JFSC can issue a direction restricting a person's ability to work in the industry at all, independent of, and in addition to, any financial penalty.
The article highlights and flags tensions: where formal status and practical consequence diverge.
None of the five points below is a genuine contradiction; nowhere in this hierarchy is a firm or individual simultaneously required to do something and prohibited from doing it. But each is a real, checkable tension between what an instrument's formal status says and what actually happens when it's ignored, and each has caught out practitioners who read only half the picture.
- “Not mandatory”, paired with real enforcement teeth. The JFSC has said in writing, twice, that Handbook guidance is not mandatory. Its own Article 21B aggravating-factors list simultaneously names failure to pay attention to relevant guidance as something that increases a penalty. Both statements are true at once: nothing compels you to follow guidance but ignoring it costs you if something else goes wrong (see Layer 4 and “How the JFSC decides whether to fine, and how much”).
- A non-mandatory document that can generate a mandatory obligation. Thematic examination feedback is formally just a type of Guidance Note. But reading it can reveal a gap in a firm's own arrangements, and acting on that gap then triggers a genuinely mandatory Code-level notification. The non-mandatory document is the trapdoor into the mandatory one (see Layer 5).
- “Code” no longer carries one consistent legal weight, and this is new since 30 June 2026. For the specific purpose of the MLCO risk-based exemption, an AML/CFT/CPF Code breach now touches a duty referenced directly in primary legislation. For the JFSC's Article 21A civil penalty power, Article 22 and Article 19 Codes have been treated identically since 2022, with no such tiering. Both are true because they're different mechanisms, but the practical effect is that the same word means two different things depending on which provision is in play (see Layer 2 and “The 2026 Tightening”).
- “No automatic liability” understates real exposure, because a second, separate power exists. Article 19(3), FS(J)L says a Code breach doesn't of itself create liability. Read alone, that's reassuring. But Article 21A, an entirely different law, lets the JFSC fine the same breach directly, without a court, without Article 19(3) liability ever needing to be established. Article 19(3)–(4) is only half the enforcement picture; reading only that half materially understates the risk (see “Enforcement Teeth”).
- “Guidelines” and “Guidance Notes” are used interchangeably in speech but carry unrelated stakes. Getting a Guidelines question wrong, the Article 36(2) “as a business” test, can mean a firm never validly registered at all, a criminal offence carrying up to seven years' imprisonment. Getting a Guidance Note wrong carries no direct legal force whatsoever. Using the two words as synonyms in a board paper or submission risks describing a criminal-law question with the vocabulary of an optional best-practice note (see Layer 3).
The article highlights the fact that the hierarchy isn't neutral: it rewards early action.
Read separately, the points below look like isolated procedural details. Read together, they're one coherent incentive structure: the hierarchy actively prices behaviour before, during, and after a contravention, not just its formal legal status.
- Following JFSC Guidance costs nothing and pays for itself later. It strengthens a “reasonable steps” defence essentially for free. Departing from it means building that case for equivalence from scratch, under scrutiny, after the fact (see Layer 4).
- Self-reporting and prompt cooperation carry a real price tag, in the firm's favour. Voluntary, prompt, and complete self-notification is an explicit mitigating factor; settling before the conclusion of Stage 1 of the JFSC's Decision-Making Process can attract a discount of up to 50% (see “How the JFSC decides whether to fine, and how much”).
- The same factors run in reverse. Failure to notify, failure to follow or implement internal recommendations, and inattention to JFSC guidance are all named, explicit aggravating factors that increase a penalty (see “How the JFSC decides whether to fine, and how much”).
- The net effect: this isn't a neutral filing system for sorting documents by legal status. It's an incentive curve, and a firm's position on it is set well before any examination or enforcement conversation begins.
The article highlights the direction of travel: what the pattern signals about where enforcement is heading.
No single fact below is new; the pattern they form together is. Two separate tracks have been tightening over this period, not one, and they shouldn't be read as a single story.
- Track one, personal liability under the AML/CFT enforcement regime: 2022 extended civil financial penalties, for the first time, to individuals: principal persons, key persons, and senior management functions, not just firms. 2023 formally designated four categories of “senior management function,” deliberately reaching below board level to compliance and risk managers whose decisions materially affect a firm's financial crime risk. 2026 hard-wired the MLCO risk-based exemption into primary legislation for the first time, creating the stronger distinction between AML/CFT Codes and Article 19 Codes described above as the two-tier Code risk. Read together, this track is a sustained expansion of who can be held personally accountable under Article 21A and how directly, not an isolated 2026 event.
- Track two, general enforcement posture on a separate statute: the 2025 Dear CEO letter to security issuers, issued under the Control of Borrowing (Jersey) Law 1947, explicitly abandoned a previously “sympathetic” approach to COBO consent breaches in favour of referral to HM Attorney General for a prosecution decision. This is not part of the AML/CFT personal-liability track above; COBO sits under an entirely different law, with no connection to Article 21A, senior management functions, or the MLCO exemption. Its value here is as a separate, equally clear example of the JFSC hardening its stated posture in writing, on a different front.
- Throughout, on both tracks: quick wins and Dear CEO letters consistently arrive years ahead of any formal Code or Handbook change, meaning they're the earliest reliable signal of where the next tightening will land, not just a record of the last one.
- Read together, these two tracks describe a regulator broadening its enforcement reach on more than one front at once, not a single narrative of personal accountability creeping outward.
IF YOU HAVE MADE IT THIS FAR, HERE IS THE ARTICLE……
What Actually Binds a Registered and Supervised Person in Jersey
A layer-by-layer guide to Jersey's legal and regulatory hierarchy, and why the label on a document is rarely the question that matters.
Executive Summary
Jersey's regulatory framework operates across several distinct instruments, not one undifferentiated body of “JFSC requirements”, and this is true across the whole regulatory perimeter, not just AML/CFT.
1. Law
- Fully binding. A breach creates direct criminal or civil liability.
- Covers both the prudential/conduct laws (Financial Services (Jersey) Law 1998, Banking Business (Jersey) Law 1991, Insurance Business (Jersey) Law 1996, Collective Investment Funds (Jersey) Law 1988) and the financial crime laws (Proceeds of Crime (Jersey) Law 1999, Money Laundering (Jersey) Order 2008, Terrorism (Jersey) Law 2002, Sanctions and Asset-Freezing (Jersey) Law 2019). See Appendix 1 for the full list.
2. Codes of Practice
- A genuine middle tier. Breach doesn't automatically create liability, but Codes are admissible in evidence, and courts must take them into account.
- Two separate statutory bases, not interchangeable: Article 22, Proceeds of Crime (Supervisory Bodies) Law (AML/CFT/CPF Codes), and Article 19, Financial Services (Jersey) Law 1998 (TCB, FSB, IB, AIF Codes).
- "Relevant Code of Practice": a 2026 legislative change (the Money Laundering (Jersey) Amendment Order 2026) inserted a statutory definition of this term into the MLO. It used it to underpin the new risk-based exemption from appointing an MLCO (Article 7(1A)–(1B)). This applies only to the Article 22 AML/CFT/CPF Codes, not the Article 19 Codes.
- Only the interpretation-and-compliance-officer provisions (Articles 1, 2, 3 and 10 of the Amendment Order) are in force, from 30 June 2026. The reliance provisions follow on 31 October 2026.
- This creates a stronger distinction between AML/CFT Codes and Article 19 Codes than existed before 30 June 2026, in the specific context of the MLCO exemption: get an AML/CFT/CPF Code point wrong on a matter touching the MLCO's risk-based exemption, and you are now touching a duty defined directly in primary legislation. Get an Article 19 Code point wrong (TCB, FSB, IB, AIF), and you remain in the older, softer position: admissible in evidence, not itself a source of automatic liability.
- That distinction is specific to the MLCO exemption mechanism. It does not extend to the JFSC's separate civil financial penalty power under Article 21A of the Commission Law, which has been able to fine for a breach of any JFSC Code, and reach individual senior managers personally, since 2022 (see “Enforcement Teeth” below).
3. Civil financial penalties
- A separate enforcement layer, sitting alongside rather than inside the Law/Code hierarchy.
- Under Article 21A, Financial Services Commission (Jersey) Law 1998, the JFSC can "fine"(civili penalty) a registered person directly, no court required, for a significant and material contravention of the MLO or any JFSC Code of Practice.
- Since the Financial Services Commission (Amendment No. 8) (Jersey) Law 2022 (in force 29 April 2022, confirmed against the enacted law text), the JFSC can equally fine a principal person, key person, or senior management function individually, where the contravention occurred with their consent, connivance, or neglect.
- This power draws no two-tier distinction between Article 22 and Article 19 Codes: it has applied equally to both, and to firms and individuals, since 2022.
4. Policy Statements incorporated by reference
- Documents such as the Outsourcing Policy and the Sound Business Policy read like guidance but acquire Code-level force where a Code expressly requires compliance with them.
5. Guidelines
- Issued under Article 36(2), Proceeds of Crime Law. A narrower instrument used specifically to interpret Schedule 2 scope, including the “when conducted as a business” test.
- Getting this wrong can mean a person has failed to register at all: a criminal offence carrying up to seven years' imprisonment.
6. Guidance Notes
- Whether in the AML/CFT/CPF Handbook or the JFSC's sector-wide papers, explicitly not mandatory.
- The JFSC confirmed this directly in its Feedback on enhancements to the AML/CFT/CPF Handbook (issued 27 November 2025), paragraph 2.13.10, page 17: "We reiterate the position that guidance is not mandatory."
- Guidance Notes function as a practical safe harbour: following them strengthens a “reasonable steps” defence; departing from them weakens it.
7. Thematic examination feedback
- Formally a type of non-mandatory Guidance Note but deserves separate billing: the JFSC expects the whole industry, not just examined firms, to read it, self-assess, and remediate.
- Failure to do so may be treated as an aggravating factor in supervision, given thematic feedback's status as a form of JFSC guidance, and acting on the findings can trigger a genuinely mandatory Code-level notification obligation.
8. Informal supervisory communications
- The JFSC's “quick wins” industry updates sit entirely outside the formal hierarchy: not Codes, Guidelines, or Handbook Guidance Notes.
- They carry no legal force but are arguably the most operationally useful documents the JFSC publishes, describing precisely what examiners are finding in practice, right now.
9. Dear CEO letters
- Addressed directly to boards, used to signal a change in supervisory posture, for example, the March 2025 letter to security issuers, which warned that breaches of Control of Borrowing consent conditions would now be referred to HM Attorney General.
- The letter itself creates no new obligation; the obligations it references were already binding law. What it signals is enforcement intent.
Layer 1: Primary Law
- At the base sits statute. It is worth naming the full range, because AML/CFT legislation tends to dominate compliance commentary. At the same time, the prudential and conduct-of-business laws that license the underlying activity get less attention, despite being no less binding (see Appendix 1).
- All of the laws in Appendix 1 are ordinary primary and subordinate legislation. Breach can create criminal or civil liability directly, without needing to reference anything the JFSC has separately published.
- The distinction between the two groups in Appendix 1 matters for how the rest of the hierarchy applies: the licensing laws each carry their own Code of Practice under Article 19, FS(J)L (or equivalent), while the financial crime laws carry the AML/CFT/CPF Codes under Article 22, POC(SB)L. A firm operating as, say, a fund services business answers to both sets simultaneously.
Layer 2: Codes of Practice
- Codes of Practice are the first JFSC instrument that carries genuine, if qualified, legal weight. There are two separate statutory bases, which is where the first common conflation happens.
- AML/CFT/CPF Codes of Practice are issued under Article 22 of the Proceeds of Crime (Supervisory Bodies) (Jersey) Law 2008.
- The regulated-business Codes, covering Trust Company Business, Fund Services Business, Investment Business, Alternative Investment Funds, and equivalents, are issued separately under Article 19 of the Financial Services (Jersey) Law 1998 (FS(J)L). Different subject matter, different legislative authority, even though both are commonly just called “the Code.”
- Their legal effect sits in a genuine middle ground between “law” and “guidance,” and each statutory base has its own express provision to this effect, not a shared one. For the Article 19 sector Codes: Article 19(3), FS(J)L provides that contravention of a Code does not of itself create liability or invalidate a transaction. In contrast, Article 19(4) provides that the Code is admissible in evidence and must be considered by a court if relevant to proceedings. For the Article 22 AML/CFT/CPF Codes: Article 22(4), POC(SB)L 2008 provides, in near-identical terms, that contravention does not of itself render a person liable to proceedings or invalidate a transaction, and Article 22(6) provides that the Code is admissible in evidence and must be taken into account by the court if relevant. The two Codes reach the same evidential position by parallel, separately worded provisions under different statutes, not by analogy.
- In practice, the JFSC treats compliance as close to mandatory: departure is a live enforcement risk even though it doesn't create automatic civil liability.
- Article 19(3)–(4) is only half the enforcement picture: the JFSC also has a direct, non-court power to fine over a Code breach (see below).
Enforcement Teeth: The JFSC's Civil Financial Penalty Powers
- Article 19(3)–(4), FS(J)L explains how a Code is treated once a matter reaches a court. It says nothing about the JFSC's own, separate power to penalise a Code breach directly, without going to court at all.
- That power sits in Article 21A of the Financial Services Commission (Jersey) Law 1998 (“the Commission Law”). Where the JFSC is satisfied a registered person has, to a significant and material extent, contravened the Money Laundering (Jersey) Order 2008 or a JFSC Code of Practice, it may impose a civil financial penalty directly, no court proceedings required.
- Since the Financial Services Commission (Amendment No. 8) (Jersey) Law 2022 (in force 29 April 2022, implementing FATF Recommendation 35), Article 21A also extends personal liability to a principal person, a key person, or a person performing a “senior management function”, each separately defined in Article 1 of the Commission Law, where the contravention occurred with their consent, connivance, or neglect, or they aided or abetted it.
- The JFSC published a Notice designating “senior management functions” on 12 January 2023, effective 13 March 2023, setting out four categories of role in scope, deliberately reaching below board level to compliance and risk managers whose decisions materially affect a firm's financial crime risk.
- Penalty bands were revised by the Financial Services Commission (Financial Penalties) (Jersey) Amendment Order 2026, signed 5 March 2026 and in force from 12 March 2026, which reintroduced maximum penalties for Bands 1, 2 and 2A for registered persons.
- As confirmed directly against the JFSC's 26 March 2026 consultation paper on the registered persons methodology: Band 1 (failure to notify the JFSC of certain matters specified in a Code of Practice): the lower of 4% of average annual turnover and £100,000. Band 2 (contravention not falling into Band 2A or 3, not rectified to the JFSC's satisfaction within the determined timeframe): the lower of 6% of average annual turnover and £4,000,000. Band 2A (contravention committed negligently): the lower of 7% of average annual turnover and £4,000,000. Band 3 (contravention committed intentionally or recklessly): 8% of average annual turnover, uncapped.
- Article 21A's fining power draws no two-tier distinction between Codes. It never has: a breach of a TCB or FSB Code has been exposed to the same direct civil penalty and personal senior-management liability as an AML/CFT/CPF Code breach since 2022, well before the 2026 amendment existed, and that remains true today. The stronger distinction introduced by the 2026 amendment (see above) is specific to the MLCO exemption mechanism under Article 7 MLO; it does not extend to this fining power.
How the JFSC decides whether to fine, and how much
- Article 21A gives the JFSC the power to fine. Article 21B of the Commission Law governs how it decides whether to use that power and the amount: a formal, statutory checklist.
- Article 21B requires the JFSC to have regard to:- the seriousness of the contravention; whether the person knew or ought to have known about it; whether it was voluntarily reported; whether steps were taken to rectify it and prevent recurrence; the need to ensure a person cannot profit from a contravention; consistency with penalties imposed in other cases; the potential financial consequences to the person and to third parties; and aggravating or mitigating factors.
- Aggravating factors include failure to take action appropriate to one's position on becoming aware of a contravention; a business model showing disregard for regulatory requirements; a previously poor compliance record; failure to pay appropriate attention to relevant JFSC guidance; failure to follow (or the absence of) internal procedures; and failure to implement internal recommendations aimed at compliance with the Codes.
- Mitigating factors: prompt and complete self-notification to the JFSC; appropriate individual action on becoming aware of an issue; full cooperation with any investigation; a previously strong compliance record; and swift procedural remediation.
- This confirms, in the JFSC's own statutory-criteria guidance, that failing to act on non-mandatory Guidance is treated as an aggravating factor when a fine is calculated, not just an informal supervisory expectation.
- The amount follows a structured methodology rather than open discretion, with separate published methodologies for registered persons and for natural persons. Both score the seriousness of the contravention against the JFSC's statutory Guiding Principles, adjust for the Article 21B factors, strip out any profit made from the contravention, and check for consistency with past penalties. Settling early in the JFSC's Decision-Making Process can attract a discount of up to 50%.
- The two methodologies diverge in one respect: penalties on registered persons scale with the firm's average annual turnover (subject to the Band caps above); penalties on natural persons are fixed maxima set out in the Schedule to the Financial Services Commission (Financial Penalties) (Jersey) Order 2015, as amended, regardless of firm size.
- Natural-person maxima, as drafted: Band 1 (failure to notify): £10,000. Band 2 (not rectified within the determined timeframe): £200,000. Band 2A (negligent contravention): £300,000. Band 3 (intentional or reckless contravention): £400,000.
- Confirmed against the JFSC's Civil Financial Penalties on Natural Persons methodology and the Schedule to the Financial Services Commission (Financial Penalties) (Jersey) Order 2015: these four figures are the correct statutory maxima, and were unchanged by the 12 March 2026 Amendment Order, which revised only the registered-person (firm) columns of the Schedule.
- The JFSC's own consultation on the 2026 changes confirms the natural-persons methodology is being reviewed separately, on its own timetable. A 2026 government consultation floated reducing the natural-person caps, but as of the current consolidated law, £400,000 remains the statutory Band 3 maximum.
- A person on the receiving end of a penalty, firm or individual, has a statutory right under Article 21F of the Commission Law to appeal to the Royal Court on the ground that the JFSC's decision was unreasonable having regard to all the circumstances.
Layer 2.5: Policy Statements Incorporated by Reference
- A hybrid category worth naming separately: it doesn't fit cleanly as either “Code” or “Guidance,” and it applies well beyond financial crime.
- The JFSC’s Outsourcing Policy originally issued 1 March 2017, current version issued 1 December 2023, effective 1 January 2024, reads on its face as a policy-and-guidance document published outside the Handbook. But the Codes of Practice for TCB, FSB, IB and AIF business each expressly require compliance with it, and the Policy itself states: “The Codes require Registered Persons to comply with the Outsourcing Policy, the requirements of which are therefore incorporated by reference as Codes requirements.”
- Compliance also feeds directly into the JFSC's Fit and Proper assessment of a registered person's structure and organisation.
- The effect: a document published and titled as “policy and guidance” acquires the same Article 19(3)–(4) status as the Code itself, purely because the Code chooses to incorporate it by reference.
- The same logic applies to the Sound Business Policy, issued jointly by the Government of Jersey and the JFSC, effective 1 November 2025, replacing the former Sound Business Practice Policy, issued under the Control of Borrowing (Jersey) Law 1947 and the Financial Services Commission (Jersey) Law 1998, entirely outside the AML/CFT framework, and again referenced in the regulated-business Codes.
- Practical lesson: a document's title or shelf location, Handbook versus standalone policy page, is not a reliable guide to its legal status. What matters is whether a Code or a Law incorporates it by reference. That has to be checked document by document.
Layer 3: Guidelines, a narrower instrument most commentary skips
- This layer gets lost because “guidelines” and “guidance notes” are used interchangeably in ordinary speech, but they are not the same instrument.
- "Guidelines" is a defined statutory term. Under Article 36(2) of the Proceeds of Crime (Jersey) Law 1999, the JFSC may issue guidelines specifically on the interpretation of Schedule 2 to that Law, most significantly, the "when conducted as a business" test that determines whether an activity falls within Schedule 2 scope at all.
- These Guidelines were originally issued 30 January 2023. A consultation on proposed amendments ran 8 December 2025 to 30 January 2026; the JFSC's proposed changes would replace the existing multi-factor “as a business” indicator test with structured “Schedule 2 gateways”: a three-part test covering the underlying activity, the “as a business” question, and Jersey nexus, not a two-limbed test.
- The distinction matters because Guidelines under Article 36(2) determine legal scope. Getting the “as a business” interpretation wrong isn't a case of falling short of best practice: it can mean a person has failed to register at all, which under Article 10(4) of the Proceeds of Crime (Supervisory Bodies) Law is a criminal offence carrying up to seven years' imprisonment and a fine, confirmed directly against the consolidated statutory text. That is a materially different risk profile from departing from a Handbook guidance note, and the two should never be described with the same word in a submission or board paper.
Layer 4: Guidance Notes
- Guidance Notes are not confined to the AML/CFT/CPF Handbook. The JFSC publishes sector-wide Guidance Notes covering areas that have nothing to do with financial crime.
- Its Compliance Monitoring guidance is a good example, originally issued 6 December 2013 (the same day as the Dear CEO letter announcing it; see Layer 7) and last revised 4 June 2026: a paper setting out an approach to compliance monitoring generally, applicable to registered persons across all sectors, not just those with AML/CFT exposure. It expressly lists the FS(J)L, the relevant sector Code, the AML/CFT legislation, and the Outsourcing Policy and Guidance Notes side by side as the minimum set of “relevant legislative and regulatory requirements” a compliance monitoring programme needs to cover.
- A second example shows a Guidance Note doing genuine interpretive work on a term the underlying law never defines. The JFSC's Guidance Note: Integrity and Competence (19 July 2018) was issued in response to the Royal Court's judgment in Francis v JFSC [2017] JRC203A, in which the Court upheld the JFSC's findings of a serious lack of integrity and competence, but recommended clearer guidance distinguishing a finding of lack of integrity from a finding of dishonesty.
- The guidance sits underneath the ongoing “fit and proper” test in Article 9 of the FS(J)L (and equivalent provisions in the Banking Business, Insurance Business, and Collective Investment Funds Laws) and Principle 1 of the Codes of Practice, which requires a registered person to conduct its business with integrity: both binding, Layer 1 and Layer 2 instruments.
- What the Guidance Note itself does is explain how the JFSC applies that binding standard: drawing on English regulatory case law, it makes clear integrity and honesty are not the same thing, and a person can lack integrity through a materially misdirected ethical compass without ever having been dishonest.
- It sets out non-exhaustive indicators of a lack of integrity, including "turning a blind eye" to matters that should raise obvious concern, failing to manage conflicts of interest, producing misleading or back-dated documents, and failing to deal with the JFSC openly and cooperatively.
- The Guidance Note has no independent legal force of its own, but a finding of serious lack of integrity or competence under the fit-and-proper test it interprets can lead directly to a public statement, a direction restricting someone's ability to work in the industry, or the civil financial penalties described above.
- Francis is the case in point: the Royal Court upheld the JFSC's public statement against the individual as a reasonable regulatory response.
- On the AML/CFT side specifically, the JFSC has been explicit, repeatedly, that Handbook Guidance Notes are not mandatory, responding to industry feedback that guidance was "often treated as mandatory in practice" with the confirmation quoted above (Feedback on enhancements to the AML/CFT/CPF Handbook, 27 November 2025, paragraph 2.13.10, page 17).
- The Handbook's own wording (Section 1) frames Guidance Notes as presenting ways of complying with the statutory requirements and Codes, and a registered and supervised person may adopt other measures provided it can demonstrate those measures achieve equivalent compliance.
- The same non-mandatory framing applies to Guidance Notes outside the Handbook, including the Compliance Monitoring and Integrity and Competence papers referenced above.
- Functionally, though, Guidance Notes operate as a safe harbour rather than a genuinely optional extra. Departing from them doesn't breach anything directly. But if a Code or statutory breach is later alleged, a firm that followed JFSC Guidance has a materially stronger evidential position: it can point to having taken reasonable steps aligned with the regulator's own published expectations. A firm that took its own approach has to build that case for equivalence from scratch, under scrutiny, after the fact.
Layer 5: Thematic Examination Feedback, “not mandatory” with real teeth
- One category of Guidance Note deserves separate attention, because it shows how much weight a “not mandatory” document can carry in practice.
- The JFSC regularly publishes thematic examination feedback papers following programmes such as its 2022 thematic examination on the role of the MLCO, with on-site examinations in Q3 2022 and feedback published 10 May 2023, and its thematic examination on countering the financing of terrorism and proliferation financing, with questionnaires and on-site examinations conducted in 2023 and feedback issued 3 October 2024. Firms are expected to consider the findings and good practice against their own arrangements, make changes where gaps are identified, and, where deficiencies exist, prepare a remediation plan, discuss it with their supervisor, and execute it.
- Critically, this expectation is addressed to the whole industry, not only to the firms that were actually examined: a registered and supervised person that was never visited is still expected to read the feedback, self-assess against it, and act.
- Because thematic feedback is itself a form of JFSC guidance, failure to act on it falls within the same aggravating-factor treatment the JFSC applies to guidance generally, and is likely to be viewed adversely in future supervisory engagement: a significant practical consequence attached to a document that is not, on its own legal status, mandatory.
- These feedback papers explicitly direct firms to "consider the notification requirements under the AML/CFT/CPF Code of Practice set out in Section 2.3 of the AML/CFT/CPF Handbook, and the relevant Codes of Practice", meaning a firm reading a piece of non-mandatory Guidance can find itself walked directly into a mandatory Code-level notification obligation once it identifies a deficiency.
- The JFSC's separate Guidance Note on Remediation Action Plans, issued April 2023, sets real expectations around timing and senior management ownership of the plan. Its own wording: “As a guide, we will have a low tolerance for plans extending beyond 12 months. However, we recognise there may be instances where completion of all actions within a plan in 12 months may not be achievable.” Ineffective or unsustainable remediation may be escalated to its Enforcement division or result in safeguarding directions.
- The lesson: “not mandatory” is a statement about the document's own legal status, not a statement about the consequences of ignoring it. A Guidance Note can sit at the bottom of the formal hierarchy and still generate consequences that feel indistinguishable from a Code breach by the time an enforcement conversation happens.
Layer 6: Informal Supervisory Communications, outside the hierarchy entirely
- It's worth closing the range out with a category that sits below even Guidance Notes in formal status, because it's easy to assume anything published by the JFSC must belong somewhere in the layers above. It doesn't.
- The clearest example is the JFSC's “quick wins” series. In January 2025, the JFSC published seven quick wins for financial crime compliance, drawn from its 2024 examination programme: gaps in SAR date and reporter information, inadequate screening records and procedures, incorrect PEP definitions, misuse of CDD exemptions, and incomplete conflicts of interest registers.
- In November 2025, it followed up with five more quick wins, adding risk appetite statements, proliferation financing risk assessment, undocumented customer risk rating changes, stale policies and procedures, and certification failures, twelve in total across the two publications.
- These documents are not Codes, not Guidelines, and not even formal Handbook Guidance Notes; they're published as ordinary “industry updates” on the JFSC news pages, with no statutory basis cited at all.
- They carry no legal force whatsoever. And yet they may be the single most operationally useful thing the JFSC publishes, because they're a direct readout of what examiners are actually finding on file review, right now, this year. A firm auditing its own AML/CFT/CPF controls gets more immediate value from checking its SAR register against the “reporter information” quick win than from re-reading the Handbook section on record-keeping in the abstract.
- The lesson: “everything the JFSC publishes” is not a closed set of tiers. There's an informal tier below Guidance Notes that carries zero legal weight but real practical value, and a compliance function that only tracks Codes and Handbook Guidance is missing some of the most current and specific signals the regulator puts out.
Layer 7: Dear CEO Letters, supervisory posture, not new obligation
- There's one more category worth distinguishing from the “quick wins” updates above, because although both sit outside the formal hierarchy, they do different jobs. Dear CEO letters are addressed specifically to boards and chief executives, not to compliance functions generally, and the JFSC uses them to signal a shift in supervisory expectation or enforcement posture, often ahead of any change to the Codes or Handbook themselves.
- They are not as frequent or as systematically catalogued as the UK FCA's portfolio letters, and the JFSC does not maintain a single dedicated archive page listing every one issued. The confirmed sequence below is therefore a verified list, not a guaranteed-complete history.
- 22 October 2010: Conflicts of Interest (trust company businesses). Requested review of internal controls on conflicts, including gifts, retrocession fees, dual directorships, and personal loans to or from client structures.
- 11 February 2011: Update to Industry. A progress update on action points from an earlier industry survey, including seminars and AML/CFT Handbook changes.
- 3 March 2011: The Role and Responsibility of the JFSC to Combat Financial Crimes. Clarified the JFSC's role relative to the Joint Financial Crimes Unit, the police, and the Law Officers: enforcement of regulatory laws versus investigation and prosecution of crime. Still referenced in JFSC material as recently as 2024.
- 16 March 2012: Annual Declarations Reminder to Registered Persons. Made a point still directly relevant today: omitting a known issue from an annual declaration because the regulator is already aware of it is not acceptable. Firms must disclose material failures, including AML/CFT breaches, together with remediation action, regardless of whether the JFSC has independently identified the issue.
- 6 December 2013: Compliance Monitoring. Announced publication of the original Compliance Monitoring guidance note (see Layer 4 above) and stressed board and senior management responsibility for approving monitoring plans and remediation. The guidance itself was subsequently revised.
- 22 January 2016: Cyber Security Reminder to Businesses. Highlighted rising cyber risk and reminded firms of Principle 3 of the Codes of Practice: organising and controlling affairs effectively, with adequate risk management systems, pointing firms to further resources.
- 15 April 2024: Interest Rate Changes, Account Acceptance and Closures. Directed at banks. Covered expectations on transparent and fair treatment of customers on savings interest rates, account acceptance, and account closures or terminations, with an emphasis on fair treatment, adequate notice, and proper governance.
- 3 March 2025: Security Issuers. Issued under the Control of Borrowing (Jersey) Law 1947 and the Control of Borrowing (Jersey) Order 1958, and covered in more detail below.
- The clearest recent illustration of what a Dear CEO letter actually does is the JFSC's letter to security issuers (3 March 2025), issued under the Control of Borrowing (Jersey) Law 1947 and the Control of Borrowing (Jersey) Order 1958. It identified failures to obtain required COBO consent, breaches of consent conditions, inadequate board oversight, failures to secure prior approval for changes to key functionaries, and failures to file required accounts.
- Critically, it changed the JFSC’s stated posture: having historically taken a "sympathetic" approach to breaches, the letter warned that breaches inconsistent with the JFSC’s guiding principles would now be referred to HM Attorney General for a prosecution decision. It also reminded boards that responsibility for COBO compliance cannot be delegated to advisers.
- Legally, this is what a Dear CEO letter is: it creates no new obligation. Breaching a COBO consent condition was already a criminal offence before the letter was sent; that's Layer 1, unchanged. What the letter does is signal enforcement intent and elevate board-level accountability for an existing obligation.
- The 15 April 2024 letter on interest rate changes, account acceptance and closures sits at the other end of this pattern: a reminder of existing standards and continued supervisory interest in governance, management information, and fair customer treatment, rather than a new rule.
- The recurring theme, whatever the subject matter, is board accountability: governance and controls must be evidenced rather than assumed, material breaches must be disclosed proactively, and customer outcomes have become an increasingly visible supervisory focus in the more recent letters. Dear CEO letters and the “quick wins” updates are typically the earliest signal available of where supervisory attention is heading earlier than a consultation, and considerably earlier than an amendment to primary legislation.
Why the Layers Get Collapsed: A Structural Cause, Not Just a Knowledge Gap
- It's worth naming why this confusion is so persistent, because “practitioners don't understand the hierarchy” undersells it.
- The Handbook physically bundles Codes of Practice and Guidance Notes together in a single document, distinguished only by a colour-coding convention. Practitioners read the Handbook end to end as one text with one register. A colour code on a page is a weak signal compared to the experience of reading fifty consecutive paragraphs in the same font, the same voice, and the same document.
- The confusion industry reported to the JFSC in the November 2025 consultation, guidance being treated as mandatory "in practice", is arguably a predictable consequence of that document design, not a failure of individual firms to read carefully enough.
- This isn't confined to AML/CFT, either. The Outsourcing Policy and Sound Business Policy sit on standalone JFSC web pages under a “Guidance and Policy” heading alongside Guidance Notes that carry no independent force at all. The page architecture itself doesn't distinguish a Policy incorporated by reference into a Code from a Guidance Note that hasn't been. The label “guidance and policy” obscures a real legal distinction underneath it.
The 2026 Tightening: "Relevant Code of Practice"
- The Money Laundering (Jersey) Amendment Order 2026 (R&O.77/2026, made 17 April 2026) inserted a new defined term into Article 1(1) of the MLO: “relevant Code of Practice,” in relation to a relevant person, meaning a Code of Practice that (a) is issued under Article 22 of the Proceeds of Crime (Supervisory Bodies) Law, and (b) applies to the relevant person in the conduct of their financial services business.
- This is not a generic tidying-up amendment. The new Article 7(1A)–(1B) requires a relevant person relying on the risk-based exemption from appointing a compliance officer to determine what is appropriate by reference to a relevant Code of Practice: this is the genuinely new hard-wiring.
- For the specific purpose of the MLCO exemption mechanism, the Article 22 AML/CFT/CPF Codes have been pulled directly into primary legislation by reference. This is a genuine narrowing of the gap between “law” and “Code”, but only for this specific purpose, and it is worth being precise about where it stops.
- Put plainly: this creates a stronger distinction between AML/CFT Codes and Article 19 Codes than existed before 30 June 2026, in the specific context of the MLCO exemption, which this article labels a two-tier “Code” risk. Get an AML/CFT/CPF Code point wrong on a matter touching the MLCO exemption, and you are touching a duty referenced directly in primary legislation. Get an Article 19 Code point wrong (TCB, FSB, IB, AIF), and you remain in the older, softer position: admissible in evidence, but not itself a source of automatic liability. A registered and supervised person can no longer safely treat “Code” as a single word with a single weight.
Two scope points worth being precise about
- “Relevant Code of Practice” only captures Article 22, POC(SB)L Codes: the AML/CFT/CPF Codes of Practice. It does not extend to the Article 19, FS(J)L Codes (TCB, FSB, IB, AIF). Those retain their existing Article 19(3)–(4) evidential status, unchanged by this amendment. It also does not touch the Policy Statements in Layer 2.5; the Outsourcing Policy and Sound Business Policy retain their existing incorporation-by-reference status.
- Commencement is staggered. Articles 1, 2, 3 and 10 of the Amendment Order, including the “relevant Code of Practice” definition and the Article 7 compliance officer amendments, came into force on 30 June 2026. The remaining articles, covering enhanced risk states and reliance provisions, do not come into force until 31 October 2026. Anything written about those reliance provisions before that date is describing a change that is not yet live.
Conclusion
- The instinct to treat “the JFSC said so” as a single tier of obligation is understandable; it's simpler, and for most day-to-day compliance decisions it doesn't lead anywhere dangerous.
- But it breaks down at exactly the moments it matters most. In a defence submission, a board report, or a decision to depart from published expectations, which tier a given requirement sits in- Law, Code, an incorporated Policy Statement, a scope-determining Guideline, or Guidance that is formally non-mandatory but carries real consequences for ignoring it- is the difference between an argument that holds and one that doesn't.
- Thematic examination feedback is the sharpest illustration of why this distinction has to be made explicitly rather than assumed. A registered and supervised person that treats a feedback paper as optional reading, because the JFSC itself calls it “not mandatory,” has correctly identified the document's formal status and drawn precisely the wrong practical conclusion: because that same document may be treated as an aggravating factor in enforcement in the same way as guidance generally, can trigger a mandatory Code-level notification once a gap is found, and starts the JFSC's low tolerance for remediation running past twelve months before it considers escalation.
- Getting the hierarchy right is not a compliance-theory exercise. It is the difference between a board that can point to a documented, timely response to published expectations, and one that discovers, after an examination, a breach, or a JFSC letter, that “it wasn't mandatory” was never the question that mattered.
Notes
A note on Practical Takeaways
- Law: licensing/conduct: Statutory basis: FS(J)L, Banking Business Law, Insurance Business Law, CIF Law (primary/subordinate legislation). Consequence of departure: Criminal/civil liability directly. Evidential status: Determinative.
- Law: financial crime: Statutory basis: POCL, MLO, Terrorism Law, Sanctions Law (primary/subordinate legislation). Consequence of departure: Criminal/civil liability directly. Evidential status: Determinative.
- AML/CFT/CPF Codes of Practice: Statutory basis: Article 22, POC(SB)L 2008. Consequence of departure: No automatic liability; now referenced in the MLCO's risk-based exemption mechanism (Art. 7(1A)–(1B) MLO, from 30 June 2026). Evidential status: Admissible; must be taken into account (Art. 22(4) and 22(6), POC(SB)L 2008, a parallel provision to Art. 19(3)–(4) FS(J)L, not an analogy).
- Regulated-business Codes (TCB, FSB, IB, AIF): Statutory basis: Article 19, FS(J)L 1998. Consequence of departure: No automatic liability. Evidential status: Admissible; must be taken into account (Art. 19(3)–(4) FS(J)L).
- Civil financial penalties: Statutory basis: Article 21A, Financial Services Commission (Jersey) Law 1998. Consequence of departure: Direct civil fine, no court required; applies to registered persons and, since 2022, to principal persons, key persons, and senior management functions personally. Evidential status: Enforceable in itself: not merely evidential; applies equally to Article 22 and Article 19 Codes and to MLO breaches.
- Policy Statements incorporated by reference: Statutory basis: Standalone JFSC/GoJ policy, incorporated into a Code. Consequence of departure: Same as the incorporating Code. Evidential status: Same as the incorporating Code once incorporated.
- Guidelines (e.g. Schedule 2 “as a business” test): Statutory basis: Article 36(2), POCL 1999. Consequence of departure: Can determine whether Schedule 2 registration applies at all; failure to register is a criminal offence (up to 7 years). Evidential status: Interpretive, but scope-determining.
- Guidance Notes (Handbook and sector-wide papers): Statutory basis: JFSC administrative publication, not statutory. Consequence of departure: None directly; weakens evidential “reasonable steps” defence if departed from. Evidential status: Not mandatory (JFSC, Nov 2025); functions as safe harbour.
- Thematic examination feedback papers: Statutory basis: JFSC administrative publication (a Guidance Note subtype). Consequence of departure: Not mandatory in itself, but failure to consider/act may be treated as an aggravating factor, consistent with the JFSC's treatment of guidance generally; can trigger a mandatory Code notification once a gap is found. Evidential status: Not mandatory, but generates real consequences via aggravating-factor treatment and downstream Code obligations.
- Informal supervisory communications (“quick wins”): Statutory basis: None: ordinary news/industry update. Consequence of departure: None; purely thematic examination feedback. Evidential status: No formal status; high practical value as a live signal of examiner focus.
- Dear CEO letters: Statutory basis: None; addressed directly to boards. Consequence of departure: None directly; elevates attention on existing legal/Code obligations, which retain their own status. Evidential status: No formal status in itself; signals supervisory posture and enforcement intent ahead of formal rule change.
A note on the State of Play: What's Actually Live (as of August 2026)
Effective dates are scattered throughout this piece. This pulls them into one chronological list, tagged by status, so the reader doesn't have to reassemble the timeline themselves.
- 29 April 2022 (Live): FSC (Amendment No. 8) (Jersey) Law 2022 in force: civil penalties extended to principal persons, key persons, and senior management functions.
- 12 January 2023 / 13 March 2023 (Live): Notice designating “senior management functions” published, then effective: four categories in scope.
- 30 January 2023 (Live, under revision): Article 36(2) Guidelines on Schedule 2 “as a business” interpretation originally issued.
- April 2023 (Live): Guidance Note: Remediation Action Plans issued.
- 10 May 2023 (Live): 2022 thematic examination feedback on the role of the MLCO published.
- 1 December 2023 / 1 January 2024 (Live): Current version of the Outsourcing Policy issued, then effective.
- 3 October 2024 (Live): 2023 thematic examination feedback on CFT/PF published.
- 12 February 2025 (Live): Civil Financial Penalties on Registered Persons methodology last revised (pre-dates the 12 March 2026 cap changes).
- 1 November 2025 (Live): New Sound Business Policy effective, replacing the former Sound Business Practice Policy.
- 27 November 2025 (Live): JFSC Handbook Feedback confirms, in writing, that guidance is not mandatory.
- 8 December 2025 – 30 January 2026 (Closed, outcome deferred): Consultation on Schedule 2 Guidelines revision ran; the JFSC has since confirmed it will not implement the revised Guidelines on the originally planned timetable.
- 12 March 2026 (Live): Financial Services Commission (Financial Penalties) (Jersey) Amendment Order 2026 in force: Band 1/2/2A caps reinstated for registered persons.
- 26 March 2026 (Closed): JFSC consultation on the registered-persons penalty methodology issued, confirming the new bands and caps.
- 17 April 2026 (Live): Money Laundering (Jersey) Amendment Order 2026 made.
- 4 June 2026 (Live): Guidance Note: Compliance Monitoring last revised.
- 30 June 2026 (Live): “Relevant Code of Practice” definition and MLCO risk-based exemption (Article 7(1A)–(1B)) in force: the stronger AML/CFT-versus-Article 19 distinction (the two-tier Code risk) begins here.
- 31 October 2026 (Upcoming, not yet live): Remaining provisions of the 2026 MLO Amendment Order come into force, including the reliance provisions.
- No new date set (Deferred): Revised Schedule 2 Guidelines: originally planned for April 2026, now deferred pending a wider package of reforms.
A Note on Terminology
- A brief note before going further, because the distinction matters and is routinely collapsed.
- The JFSC’s own Guidance Note on Remediation Action Plans defines "registered person" as a person registered or holding a permit under the Collective Investment Funds (Jersey) Law 1988, the Banking Business (Jersey) Law 1991, the Insurance Business (Jersey) Law 1996, or the Financial Services (Jersey) Law 1998.
- It separately extends its scope to "a person supervised by the JFSC using powers in the Proceeds of Crime (Supervisory Bodies) (Jersey) Law 2008 for compliance with the JFSC’s AML/CFT/CPF Codes of Practice and related legislation." These are not automatically the same population: a DNFBP, such as a law firm or estate agency, can be supervised by the JFSC for AML/CFT/CPF purposes under POC(SB)L powers without being a "registered person" under any of the licensing laws at all.
- This article therefore uses "registered and supervised persons" throughout to capture both groups, rather than defaulting to either term alone.
A Note on the Term “Two-Tier Code Risk”
- “Two-tier Code risk” is this article's own term. It does not appear in the Money Laundering (Jersey) Amendment Order 2026, in any JFSC publication, or in any other source cited in this article. It is used here as a label for an effect this article identifies and documents, not as a quotation or paraphrase of language used by the JFSC or the legislature.
- The underlying facts the label describes are independently sourced and set out in full above, and are not in dispute in this article: (1) the Money Laundering (Jersey) Amendment Order 2026 inserted a statutory definition of “relevant Code of Practice” into Article 1(1) of the MLO; (2) that definition is used in the new Article 7(1A)–(1B) risk-based exemption from appointing a compliance officer; (3) the definition, and therefore this mechanism, captures only Codes issued under Article 22 of the Proceeds of Crime (Supervisory Bodies) (Jersey) Law 2008, not the Article 19 Codes issued under the Financial Services (Jersey) Law 1998; and (4) this creates a difference in legal treatment between the two categories of Code, in the specific context of that exemption mechanism, that did not exist before 30 June 2026.
- “Two-tier Code risk” is this article's characterisation of point (4). A reader, including the JFSC, is free to disagree with the characterisation without disputing the four underlying facts it is built on, each of which is sourced to primary legislation or the JFSC's own published material elsewhere in this article.
- This article does not attribute the phrase, or any variant of it, to the JFSC at any point, and readers citing this analysis should not present “two-tier Code risk” as JFSC or statutory terminology. Where precision matters more than memorability, for example in a formal submission to the JFSC or in Court, the more neutral formulation used alongside it throughout this article, a stronger distinction between AML/CFT Codes and Article 19 Codes in the context of the MLCO exemption, is the more defensible phrasing to rely on directly.
Appendix 1: Laws
Referenced above under Layer 1 (“see Appendix 1 for the Laws”) and in the Executive Summary. One appendix; referenced consistently throughout.
Financial services regulatory laws (license and govern the conduct of financial services business itself)
- Financial Services Commission (Jersey) Law 1998: establishes the JFSC and its statutory functions.
- Financial Services (Jersey) Law 1998 (FS(J)L): governs investment business, trust company business, fund services business, general insurance mediation business, and money service business.
- Banking Business (Jersey) Law 1991.
- Insurance Business (Jersey) Law 1996.
- Collective Investment Funds (Jersey) Law 1988.
- Control of Borrowing (Jersey) Law 1947, together with the Control of Borrowing (Jersey) Order 1958 (COBO).
Financial crime laws (apply across sectors regardless of which licensing regime a firm operates under)
- Proceeds of Crime (Jersey) Law 1999.
- Proceeds of Crime (Supervisory Bodies) (Jersey) Law 2008.
- Money Laundering (Jersey) Order 2008 (MLO).
- Terrorism (Jersey) Law 2002.
- Sanctions and Asset-Freezing (Jersey) Law 2019.
Sources
Verified links are shown below with their full web addresses. Where a working, independently-verified link could not be confirmed in this fact-check pass, that is flagged rather than guessed; please locate and insert the correct link before publishing.
- JFSC, Feedback on enhancements to the AML/CFT/CPF Handbook (27 November 2025): quote confirmed at para. 2.13.10, page 17
- JFSC, Civil Financial Penalties on Registered Persons: methodology (percentages confirmed; caps effective 12 March 2026 not yet reflected on this page as at last revision)
- JFSC, Consultation on amendments to the civil financial penalty methodology for registered persons (26 March 2026): confirms Band 1–3 percentages and caps, and the 5/12 March 2026 dates
- Jersey Legal Information Board, Financial Services Commission (Financial Penalties) (Jersey) Amendment Order 2026 (RO-020-2026)
- Jersey Legal Information Board, Financial Services Commission (Financial Penalties) (Jersey) Order 2015 (consolidated)
- JFSC, Civil Financial Penalties on Natural Persons: methodology
- JFSC, Decision-Making Process
- JFSC, Our Approach to Enforcement: confirms a public statement is issued whenever a civil financial penalty is imposed
- JFSC, Civil Financial Penalties on Registered Persons: current methodology PDF (updated 12 February 2025)
- JFSC, Consultation on amendments to the JFSC’s civil financial penalty methodology for registered persons
- Jersey Legal Information Board, Financial Services Commission (Amendment No. 8) (Jersey) Law 2022
- Jersey Legal Information Board, Financial Services Commission (Jersey) Law 1998 (consolidated)
- Jersey Legal Information Board, Money Laundering (Jersey) Amendment Order 2026 (R&O.77/2026)
- Jersey Legal Information Board, Money Laundering (Jersey) Order 2008 (consolidated)
- Jersey Legal Information Board, Proceeds of Crime (Supervisory Bodies) (Jersey) Law 2008 (consolidated) — confirms Article 22(4)–(6) evidential provisions and Article 10(4) seven-year maximum for unauthorised Schedule 2 business
- Appleby, Civil Financial Penalties Regime: The Scope of “Senior Management Function”
- Baker & Partners, 2026 Jersey White-Collar Crime Trends
- Comsure, “Relevant Code of Practice”: the most significant conceptual change in Jersey’s 2026 AML amendment
- Comsure, All change for MLCOs in Jersey after the Money Laundering (Jersey) Amendment Order 2026
- Comsure, Jersey: Money Laundering (Jersey) Amendment Order 2026 – June/October 2026
- Comsure, Is JFSC AML/CTF/CPF guidance mandatory?
- Comsure, JFSC Codes vs Guidance: what is mandatory (and why) in the updated AML/CFT/CPF Handbook
- Government of Jersey, Consultation Paper: The MLCO Role (January 2026)
- Royal Court of Jersey, Francis v JFSC [2017] JRC203A (4 December 2017): judgment
- Royal Court of Jersey, Francis v JFSC [2017] JRC203A: PDF
- JFSC, Five more quick wins for financial crime compliance (6 November 2025): confirms January 2025 (seven) and 6 November 2025 (five more)
- JFSC, Important update: new Sound Business Policy effective 1 November 2025
- JFSC, Dear CEO: Conflicts of Interest (22 October 2010)
- JFSC, Dear CEO: Update to Industry, February 2011 (11 February 2011)
- JFSC, Dear CEO: The Role and Responsibility of the JFSC to Combat Financial Crimes (3 March 2011)
- JFSC, Dear CEO: Annual Declarations Reminder to Registered Persons (16 March 2012)
- JFSC, Dear CEO: Compliance Monitoring (6 December 2013)
- JFSC, Dear CEO: Cyber Security Reminder to Businesses (22 January 2016)
- JFSC, Dear CEO: Interest Rate Changes, Account Acceptance and Closures (15 April 2024)
- JFSC, Dear CEO: Security Issuers (3 March 2025)
- JFSC, Civil Financial Penalties on Natural Persons: methodology (maxima confirmed: £10,000 / £200,000 / £300,000 / £400,000)
- Jersey Legal Information Board, Financial Services Commission (Financial Penalties) (Jersey) Order 2015 (consolidated, Schedule)
- JFSC, Guidelines on interpretation of Article 36 of the Proceeds of Crime (Jersey) Law 1999 (30 January 2023)
- JFSC, Consultation on Schedule 2: proposed amendments to the Article 36 guidelines (8 December 2025 – 30 January 2026)
- JFSC, Feedback statement: Schedule 2 Guidelines: confirms deferral of the planned April 2026 implementation
- JFSC, Notice designating “senior management functions” (published 12 January 2023, effective 13 March 2023)
- JFSC, Notice designating “senior management functions”: news announcement
- JFSC, Trust Company Business Code of Practice
- JFSC, Fund Services Business Code of Practice
- JFSC, Outsourcing Policy: current version
- JFSC, Outsourcing Policy: landing page
- JFSC, Guidance Note: Compliance Monitoring (originally 6 December 2013, last revised 4 June 2026)
- JFSC, Guidance Note: Integrity and Competence (19 July 2018)
- JFSC, 2022 thematic examination programme on the role of the MLCO: examination findings
- JFSC, The role of the Money Laundering Compliance Officer: thematic feedback published (10 May 2023)
- JFSC, 2023 thematic examination feedback: countering the financing of terrorism and proliferation financing (issued 3 October 2024)
- JFSC, Guidance Note: Remediation Action Plans (issued April 2023)
- JFSC, Guidance on remediation action plans: news announcement
The Team
Meet the team of industry experts behind Comsure
Find out moreLatest News
Keep up to date with the very latest news from Comsure
Find out moreGallery
View our latest imagery from our news and work
Find out moreContact
Think we can help you and your business? Chat to us today
Get In TouchNews Disclaimer
As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.