Code

CSP Code of Practice (December 2019)

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is the Bermuda Monetary Authority's Code of Practice issued under section 7 of the Corporate Service Provider Business Act 2012. It sets out the standards, procedures and sound principles that licensed corporate service providers (CSPs) must have regard to in conducting their business, applying a proportionality principle based on each licensee's nature, scale and complexity.

  • Client due diligence: CSPs must have risk-based CDD procedures, comply with AML/ATF legislation, know the current identity of directors, partners, officers and beneficial owners on an ongoing basis, and verify the source of client monies held.
  • Governance and board practices: CSP companies must have a board comprised solely of individuals (no corporate directors), maintain minutes evidencing decisions and location of meetings, and satisfy the physical presence requirement under section 4A of the Act.
  • Internal controls and record keeping: CSPs must keep and preserve appropriate records in Bermuda, maintain adequate personnel, systems and controls, and segregate and safeguard client funds.
  • Conflicts of interest and confidentiality: CSPs must document policies to manage conflicts of interest, disclose material interests, and observe confidentiality obligations regarding client information while not misleading third parties on beneficial ownership.
  • Nominee shareholder agreements: Where a CSP acts as or arranges a nominee shareholder, it must have a written nominee agreement identifying the beneficial owner and retain a copy.
  • Risk management framework: CSPs must implement a risk management framework commensurate with their business scale and risk profile, with board oversight.
  • Advertising and disclosure: CSPs must advertise responsibly and ethically, and disclose their licensed status on websites, advertisements and correspondence.
  • Cooperation with regulators: CSPs must cooperate openly with the Authority and proactively report material developments such as staffing changes, cybersecurity incidents, criminal proceedings, or business sale/amalgamation.

Failure to comply with the Code is not itself an offence, but the Authority takes compliance into account when assessing whether a licensee's business is conducted prudently, and persistent non-compliance may lead to formal enforcement action.

Key obligations

  • Carry out risk-based client due diligence before agreeing to act for any new client and comply with Bermuda's AML/ATF legislation
  • Maintain ongoing knowledge of the current identity of directors, partners, officers and, to the fullest extent possible, beneficial owners of client entities
  • Verify the source of client monies held to ensure they are not of illicit origin
  • Ensure boards of CSP companies are comprised solely of individuals and keep minutes of board, partner and management meetings evidencing decisions and location
  • Maintain documented policies and procedures for delegation, conflicts of interest, and client engagement/acceptance decisions
  • Keep and preserve appropriate business records in Bermuda
  • Enter into and retain written nominee shareholder agreements identifying the beneficial owner where nominee services are provided
  • Implement a risk management framework commensurate with the scale and risk profile of the business, with board oversight
  • Advise employees and other persons with access to confidential information in writing about confidentiality obligations upon engagement and periodically thereafter
  • Maintain a documented, transparent complaints handling process with written records of complaints, responses and actions taken
  • Disclose licensed status on websites, advertisements and correspondence
  • Proactively alert the Authority to material business developments such as staffing changes, systems changes, insurance claims, criminal proceedings, amalgamations, business sales, cybersecurity incidents, or licensing criteria issues

Applies to

corporate service providers, holders of corporate service provider licences, holders of limited corporate service provider licences

Topics

Version history

2026-07-07

source file (current)