Code
Digital Asset Business Act 2018 - Code of Practice (April 2023)
Status not confirmedView on BMA's website Source document
Summary
This Code of Practice is issued by the Bermuda Monetary Authority under Section 6 of the Digital Asset Business Act 2018 to set out the standards, procedures and sound principles that licensed digital asset businesses (DABs) must observe. It should be read alongside the DAB Statement of Principles, and the Authority applies its provisions proportionately based on each DAB's nature, scale, complexity and risk profile. Failure to adhere to the Code is a factor the Authority will weigh when assessing whether a licensee is conducting business in a sound and prudent manner.
- Corporate governance: DABs must maintain a sound governance framework with an effective board that oversees strategy, risk, fitness and propriety of officers, conflicts of interest and delegation/outsourcing arrangements.
- Senior representative: Every DAB must appoint an approved senior representative maintaining an office in Bermuda, knowledgeable in digital asset business and local law, who monitors compliance and reports certain events under Section 20 of the Act.
- Risk management: DABs must establish a risk management function with documented policies (including cybersecurity and client private key storage policies), risk identification/assessment/monitoring processes, and controls such as additional sign-off for wallet-to-wallet asset transfers based on value.
- Client due diligence and asset protection: Requirements cover client due diligence, segregation and protection of client assets, accounting and record-keeping, adequate staffing, and cyber risk controls.
- Internal controls: DABs must maintain internal audit and compliance functions, conduct self-assessments, and report operational risk incidents.
- Outsourcing: Delegated or outsourced functions remain subject to board oversight, and outsourcing arrangements must not frustrate the Authority's supervisory access.
- Conduct of business: Covers integrity and ethics, market integrity, conflicts of interest, fair treatment of clients (including vulnerable clients), product due diligence, advertising, sales practices, client communications, disclosure, suitability, client agreements, and conducting business online.
- Confidentiality and complaints: DABs must preserve client confidentiality, maintain a documented complaints handling framework with a complaint register, and publish complaint contact information.
- Closed and inactive accounts: DABs must publish criteria for account closure/inactivity, give clients reasonable notice, and promptly return client funds on closure where appropriate.
- Cooperation with regulators: DABs must deal openly and cooperatively with the Authority and ensure third-party contracts do not impede the Authority's supervisory access.
The Code operates as supervisory guidance under the Act rather than standalone binding rules, but non-compliance is taken into account by the BMA in assessing whether a licensee meets its statutory obligation to conduct business in a sound and prudent manner.
Key obligations
- DABs must establish and maintain a sound corporate governance framework with an effective, adequately resourced board.
- DABs must appoint an approved senior representative who maintains an office in Bermuda and is knowledgeable in digital asset business and Bermuda law.
- DABs must establish a risk management function with documented risk, cybersecurity and client private key storage policies.
- DABs must require additional senior management sign-off for wallet-to-wallet asset transfers based on the amount transferred.
- DABs must segregate and protect client assets and maintain adequate accounting and record-keeping systems.
- DABs must maintain independent internal audit and compliance functions and conduct periodic self-assessments.
- DABs must report operational risk incidents.
- DABs must implement a documented complaints management framework, including a complaint register, and make complaint handling information publicly accessible.
- DABs must publish criteria for deeming accounts inactive or closed and provide clients reasonable notice and assistance before closing or deactivating accounts.
- DABs must promptly return client funds upon account closure or deactivation where appropriate and allowable by law.
- DABs must ensure outsourcing and third-party contracts do not frustrate the Authority's supervisory or regulatory access.
- DABs must preserve the confidentiality of client information and advise staff and outsourced partners in writing of confidentiality obligations.
Applies to
Digital Asset Business (DAB) licensees
Related documents
- This document is made under Digital Asset Business Act 2018