Code

Insurance Marketplace Provider Code of Conduct (31 December 2019)

Bermuda Monetary Authority (BMA) · Bermuda

In force

Current version last checked: 2026-07-07

Summary

This is the Bermuda Monetary Authority's Code of Conduct for registered Insurance Marketplace Providers, issued under section 2BA of the Insurance Act 1978. It sets out governance, operational, client protection and cooperation standards that the Authority expects Insurance Marketplace Providers to meet, applying a proportionality principle based on each provider's nature, scale and complexity.

  • Governance and fitness: Controllers and officers must meet fit and proper criteria, and the provider must implement a documented corporate governance framework and appoint qualified board members.
  • Prudent business conduct: Boards and senior management must maintain adequate staffing, controls, pre-vetting of new clients, cyber security, and hold adequate insurance including professional liability cover.
  • Records and reporting: Providers must keep adequate accounting and record-keeping systems in Bermuda and ensure prudential filings and regulatory applications are timely and accurate.
  • Client relationships and disclosures: Providers must act with due skill and care, safeguard client monies, disclose fee structures and licensing status, keep client information confidential, and maintain a documented complaint handling procedure.
  • Risk and compliance controls: Providers must maintain business continuity/disaster recovery plans, conflicts of interest policies, anti-fraud measures, and AML/CFT and sanctions compliance procedures, including client due diligence for direct long-term business.
  • Outsourcing and reputation: Providers must perform due diligence on outsourced service providers while the board retains ultimate responsibility, and must avoid bringing Bermuda's reputation into disrepute.
  • Regulatory cooperation: Providers must notify the Authority of material business changes and must give written notice of anticipated non-compliance, staff fraud or dishonesty, material changes to indemnity cover, or material cyber breaches.

The Code took effect immediately upon publication on 31 December 2019, but the Authority set a compliance deadline of 1 January 2021 for Insurance Marketplace Providers to fully implement its requirements.

Key obligations

  • Controllers and officers of an Insurance Marketplace Provider must meet fit and proper person criteria and the provider must consider a candidate's fitness before appointment.
  • The provider must notify the Authority immediately of material concerns about a controller or officer's appropriateness or professionalism, and advise of remediation actions.
  • The provider must implement a documented corporate governance framework and appoint qualified individuals to its board.
  • The provider must maintain adequate accounting, financial and record-keeping systems and controls, and preserve appropriate records in Bermuda.
  • The provider must hold adequate insurance coverage, including professional liability insurance, proportional to its risk profile.
  • The provider must have safeguards to protect client funds, including separate client trust accounts where client monies are held.
  • The provider must have a documented fee structure disclosed to clients, including notice of any changes to fees or services.
  • The provider must provide clients with written terms of business including service description, fees, termination terms, and a statement of licensing by the Authority.
  • The provider must document and implement confidentiality, cyber risk management, and data retention policies for client and insurer information.
  • The provider must have a documented complaint handling procedure communicated to clients, policyholders and insurers, including a complaint register.
  • The provider must document and test a business continuity and disaster recovery plan.
  • The provider must have documented conflicts of interest policies, disclosing conflicts to clients and declining to act where conflicts cannot be mitigated.
  • The provider must have documented anti-fraud policies and procedures.
  • Providers dealing with direct long-term business must carry out client due diligence before acting for a new client and comply with AML/CFT legislation and international sanctions.
  • The provider must perform due diligence on outsourced service providers and ensure outsourced functions meet in-house standards.
  • The provider must give the Authority written notice of anticipated non-compliance, staff fraud/dishonesty, material changes to indemnity cover, or material cyber breaches.
  • The provider must notify the Authority of proposed material changes to its business plan and significant operational developments.
  • Providers must achieve full compliance with the Code by the established deadline.

Applies to

Insurance Marketplace Providers

Deadlines

  • 1 January 2021: Established deadline for Insurance Marketplace Providers to achieve compliance with the Code.
  • immediately upon publication: The Code came into effect immediately when published on 31 December 2019.

Related documents

Topics

Version history

2026-07-07

source file (current)