Circular
Stakeholder Letter - Operational Cyber Risk Management Code of Conduct (2022-03-14)
IssuedView on BMA's website Source document
Summary
This is a BMA stakeholder letter summarising industry feedback on the consultation for the Operational Cyber Risk Management Code of Conduct and confirming the Code's finalisation and commencement. It explains key changes made in response to comments and sets out when affected entities must be compliant.
- Scope: Applies to Banks, Deposit Companies, Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (Relevant Licensed Entities, RLEs).
- Interpretation: Clarifies that Code requirements using 'should' are encouraged but not mandatory, and compliance will be assessed proportionately to an RLE's nature, scale and complexity.
- Key revisions: Amendments made to sections on the CISO role (permitting reliance on a group CISO), outsourcing/third-party cyber risk wording, notification of cyber risk reporting events (a sample reporting guide to be published), network security management (removal of 'demilitarised zone' reference), use of cryptography (modules must be 'enabled' rather than merely 'included'), and the definition of data loss prevention.
- Commencement: The Code comes into force on 15 March 2022 for Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers, with an in-force date for Banks and Deposit Companies to be announced separately.
RLEs within the sectors covered by the 15 March 2022 commencement must achieve full compliance with the Code by 15 February 2023.
Key obligations
- RLEs covered by the 15 March 2022 commencement (Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers) must become fully compliant with the Operational Cyber Risk Management Code of Conduct by 15 February 2023.
- RLEs must evaluate cryptographic implementations to ensure only cryptographic modules based on authoritative standards and reputable protocols are enabled.
- RLEs must comply with the notification of cyber risk reporting events requirement in Section XXIV, using the sample reporting guide the Authority will publish.
- Banks and Deposit Companies must await and then comply with a separately communicated in-force date for the Code.
Applies to
Banks, Deposit Companies, Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses, Fund Administration Providers
Deadlines
- 15 March 2022: Code comes into force for Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers.
- 15 February 2023: Deadline for Relevant Licensed Entities in the above sectors to become fully compliant with the Code.
- to be communicated at a later date: In-force date of the Code for entities licensed under the Banks and Deposit Companies Act 1999.
Topics
Version history
2026-07-07