Code

Digital Asset Business Custody Code of Practice (February 2024)

Bermuda Monetary Authority (BMA) · Bermuda

In force

Current version last checked: 2026-07-07

Summary

This Code of Practice, issued by the Bermuda Monetary Authority under the Digital Asset Business Act 2018, sets out detailed operational standards for any Digital Asset Business (DAB) that acts as a custodian of clients' digital assets, meaning it holds sole or partial control over client private keys. It supplements the general DAB Code of Practice and the DAB Operational Cyber Risk Management Code, and should be read alongside them. Non-compliance is taken into account by the Authority when assessing whether a licensed DAB is conducting business in a sound and prudent manner.

  • Business controls: DABs must have documented liquidity assessment mechanisms, a hot/cold storage risk assessment, fraud detection and compliance protocols, formally approved custody roles and responsibilities, adequate insurance or other loss protections, and collusion mitigation controls over signing processes.
  • Proof of reserves: Custodians must maintain sufficient amounts of each digital asset type to meet client obligations, with adequate accounting, record-keeping, segregation of duties and business continuity arrangements to access records at all times.
  • Seed and key generation: Seeds must use a compliant random bit generator with at least 256-bit entropy, encoded into a minimum 24-word mnemonic phrase and hashed to at least 512-bit; at least three individuals must be involved in seed creation with no single person holding the whole seed, and seed creators must be excluded from transaction signing.
  • Key management and compromise procedures: DABs must formally document seed/key storage, backup and access-control procedures (including splitting backup seed phrases across locations, strong encryption, and recommended use of FIPS 140-2 certified HSMs), plus documented key compromise and immediate key revocation procedures with full audit trails.
  • Transaction handling: Multi-signature authorisation and transaction authorisation controls must be implemented, with periodic transaction audits and full audit trails of all user and admin actions retained for review.
  • Audit requirements: An annual IT audit plan must be approved by the board's audit committee (or equivalent); specified custody processes (key/seed management, key revocation, multi-signature authorisation, transaction audit logs, suspicious transaction handling, storage migration, proof of solvency) must be audited at least every six months, with transaction audit log elements audited quarterly.
  • Record retention: Risk assessments, audit evidence and audit records must be retained for at least five years and made available to the BMA upon request.

The Code applies proportionately according to each DAB's nature, scale, complexity and risk profile, and DABs must implement standards at least equivalent to those prescribed, escalating controls where their risk profile or emerging best practice warrants it. Where custody is outsourced to a qualified custodian, the DAB remains responsible for satisfying itself that the third party maintains comparable standards.

Key obligations

  • DABs must document mechanisms to assess liquidity needs for trading and client transactions.
  • DABs must complete a documented risk assessment for hot and cold storage arrangements.
  • DABs must develop and maintain a fraud detection and compliance protocol, including suspicious transaction detection and review procedures.
  • DABs must formally document and have senior management approve custody operational roles and responsibilities.
  • DABs must demonstrate appropriate insurance or other financial protections for assets under custody.
  • DABs must maintain sufficient amounts of each digital asset type in custody to meet client obligations, with adequate records and systems to track ownership (proof of reserves).
  • DABs must implement collusion mitigation controls over the transaction signing process and address collusion risk in recurring operational risk assessments.
  • DABs must generate seeds with at least 256-bit entropy encoded into a minimum 24-word mnemonic phrase, hashed to at least 512-bit, using at least three individuals with no single person holding the full seed.
  • DABs must exclude seed creators from transaction signing and key access systems.
  • DABs must use an industry-standard key generation method ensuring revoked signatories cannot access backup seeds.
  • DABs must implement secure deletion/destruction mechanisms after seed and key generation.
  • DABs must formally document a seed and key management procedure covering encryption, storage location controls, splitting of backup seed phrases, and separate backup storage.
  • DABs must maintain a formal key access and compromise procedure with an audit trail of access changes, including a response mechanism for compromised seeds/keys.
  • DABs must have a key revocation procedure enabling immediate revocation of a signatory's access.
  • DABs must implement multi-signature authorisation and transaction authorisation requirements, with periodic transaction audits.
  • DABs must maintain a full audit trail of user/admin actions and transaction details, retained for at least five years and available to the BMA.
  • DABs must develop and have the board's audit committee (or equivalent) approve an annual IT audit plan.
  • DABs must audit specified custody processes (seed/key management, key revocation, multi-signature authorisation, transaction audit logs, suspicious transaction handling, storage migration, proof of solvency) at least every six months, with transaction audit log components audited quarterly.
  • DABs must retain audit records for at least five years and make them available to the BMA upon request.
  • DABs must document risk assessments and retain them for at least five years, available to the BMA upon request.
  • Where custody is outsourced to a qualified custodian, the DAB must satisfy itself that the custodian maintains comparable standards to those in the Code.

Applies to

Digital Asset Businesses (DABs), custodians of digital assets, qualified custodians

Deadlines

  • every six months (minimum): Recurring audit of specified custody processes such as key/seed management, key revocation, multi-signature authorisation, transaction audit logs, suspicious transaction handling, storage migration and proof of solvency.
  • quarterly: Audit of transaction system audit log elements (contractual nature of evidence, proof of evidence, proof of elapsed time, completed transaction audit).
  • annually: Development and board audit committee approval of an IT audit plan.
  • at least five years: Retention period for risk assessments, audit records and transaction audit logs, to be made available to the BMA upon request.

Related documents

Topics

Version history

2026-07-07

source file (current)