Code
Digital Asset Business Code of Practice (April 2022)
Status not confirmedView on BMA's website Source document
Summary
This Code of Practice, issued by the Bermuda Monetary Authority under section 6 of the Digital Asset Business Act 2018, sets out the standards, procedures and sound principles that licensed digital asset businesses (DABs) must observe to conduct business in a sound and prudent manner. It is applied proportionately according to each DAB's nature, scale, complexity and risk profile, and is to be read alongside the DAB Statement of Principles.
- Corporate governance: The board bears ultimate responsibility for governance and oversight, must have appropriate composition and expertise, and must ensure fitness and propriety assessments, conflict of interest management and effective oversight of chief and senior executives.
- Senior representative: Every DAB must appoint a senior representative (based in Bermuda except for Class T licensees) who monitors ongoing compliance with the Act and reports certain events to the Authority under section 20.
- Risk management framework: DABs must establish a risk management function with clearly defined roles, key policies (including cybersecurity, private key storage and AML/ATF policies), measurement and stress-testing techniques, and controls such as multi-signature approval for wallet-to-wallet asset transfers.
- Client due diligence and monitoring: DABs must perform due diligence before onboarding clients, verify true identity, retain KYC records, provide AML training, and comply with the Proceeds of Crime Act, POCR and Anti-Terrorism (Financial and Other Measures) Act.
- Internal controls: Requirements cover segregation and protection of client assets, competent management, delegation, record-keeping, adequate staffing, cyber risk controls, internal audit and compliance functions, fee disclosure, client agreements and complaint handling, and conflicts of interest policies.
- Operational risk incident reporting: Any interruption to an operational procedure must be documented (cause, impact, resolution, timeline) and reported to senior leadership and the board, with a timeline set for implementing resulting policy changes.
- Outsourcing: Outsourced functions remain the DAB's responsibility; the board must assess impacts before outsourcing and ensure service agreements do not impede the Authority's access to data or cooperation.
- Cooperation with regulators: DABs must deal openly with the Authority and other regulators and ensure contracts do not impede the Authority's supervisory access.
Non-compliance with the Code is not itself a separate offence but will be taken into account by the Authority when assessing whether a licensed DAB is meeting its statutory obligation to conduct business in a sound and prudent manner.
Key obligations
- DABs must establish and maintain a sound corporate governance framework with an effective board exercising oversight of risk management, internal controls, and delegated or outsourced activities.
- DABs must appoint an approved senior representative, maintaining a head office in Bermuda (except Class T licence holders), who reports certain events to the Authority under section 20 of the Act.
- DABs must establish a risk management function with documented policies (risk, cybersecurity, private key storage, AML/ATF policies) and require additional senior management signatures for wallet-to-wallet asset transfers based on transfer amount.
- DABs must conduct client due diligence prior to onboarding, verify client identity, retain KYC and identification records, and provide AML training to staff in compliance with the Proceeds of Crime Act, POCR and Anti-Terrorism (Financial and Other Measures) Act.
- DABs must segregate and protect client assets, maintain adequate accounting and record-keeping, ensure adequate and vetted personnel, and maintain internal audit and compliance functions.
- DABs must document and report operational risk incidents (cause, impact, resolution, timeline) to senior leadership and the board, and establish a timeline for implementing resulting policy or procedure changes.
- DABs must ensure oversight and accountability for any outsourced functions, assess impacts before outsourcing, and ensure service agreements do not restrict the Authority's access to data or cooperation.
- DABs must maintain conflict of interest policies covering board, staff and service providers, including measures to prevent market manipulation such as insider trading or pump and dump schemes.
- DABs must deal openly and cooperatively with the BMA and other relevant regulatory authorities, ensuring contracts do not impede regulatory supervision.
Applies to
Digital asset businesses (DABs) licensed under the Digital Asset Business Act 2018, Class T (test) licence holders
Related documents
- This document is made under Digital Asset Business Act 2018