Code

Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15)

Bermuda Monetary Authority (BMA) · Bermuda

In force

Current version last checked: 2026-07-07

Summary

This Bermuda Monetary Authority Code of Conduct sets out mandatory operational cyber risk management standards for Relevant Licensed Entities (RLEs) across five licensed sectors. It implements the statutory requirement that these entities conduct business in a prudent manner by maintaining 'adequate systems' that address cyber risk, and failure to comply is treated by the BMA as evidence of failing that prudential threshold.

  • Governance: Boards and senior management must oversee cyber risk, approve a cyber risk policy at least annually, and appoint a Chief Information Security Officer (who may be outsourced) to deliver an operational cyber risk management programme.
  • Risk assessment and controls: RLEs must run a documented risk assessment process (identification, measurement, response, monitoring/reporting), maintain an asset inventory with classification, and risk-assess outsourcing, cloud computing, end-user computing and new IT projects.
  • Detect and protect controls: Requirements cover IT service management, threat intelligence, incident management, logical access, data classification and loss prevention, malicious code protection, patch management, network security, secure application development, logging/monitoring and cryptography.
  • Response and recovery: RLEs must implement Business Continuity Planning and Disaster Recovery policies, including regular business impact analysis and at least annual testing of BCP/DR plans.
  • Reporting to the Authority: The Code requires notification of cyber reporting events to the Authority and expects supporting documentation (e.g. risk assessments) to be retained and produced on request.

The Code applies proportionately to the nature, scale and complexity of each RLE's business rather than as a one-size-fits-all standard, and should be read alongside the BMA's Outsourcing Guidance Notes 2019. It entered into force on 15 March 2022, with full compliance required by 15 February 2023.

Key obligations

  • Boards must have oversight of cyber risk and approve a cyber risk policy at least annually, with regular updates provided to the board and senior management.
  • RLEs must implement an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls.
  • RLEs must appoint a Chief Information Security Officer with appropriate qualifications or experience, who may be an outsourced resource but with the board retaining oversight responsibility.
  • RLEs must document their risk assessment process and retain records for at least five years, available to the Authority upon request.
  • RLEs must maintain oversight and accountability for outsourced functions, including service agreements covering compliance with jurisdictional laws, cooperation with the Authority, and timely access to data and records.
  • RLEs must risk-assess the use of cloud computing, including governance, legal, compliance/audit and information governance considerations, and define roles/responsibilities for each control.
  • New projects involving critical data or systems must undergo a technology risk assessment before implementation.
  • RLEs must notify the Authority of cyber reporting events.
  • RLEs must complete an assessment of logging and monitoring requirements, retain and protect system event logs, and monitor for anomalous or malicious activity.
  • RLEs must implement Business Continuity and Disaster Recovery plans, including regular business impact analysis, and test BCP/DR plans at least annually with documented results and remediation tracking.
  • RLEs should review the adequacy of their cyber insurance coverage at least annually.
  • RLEs must comply with the Code's requirements by 15 February 2023.

Applies to

corporate service providers, trust companies, money service businesses, investment businesses, fund administration providers

Deadlines

  • 15 March 2022: Date the Code comes into force.
  • 15 February 2023: Deadline by which RLEs are required to comply with the Code.
  • annually: Board must approve the cyber risk policy at least annually.
  • annually: BCP and DR plans must be tested at least annually, with results documented.
  • annually: RLEs should review the adequacy of their cyber insurance coverage at least annually.
  • at least five years: Risk assessments must be documented and retained for at least five years, available to the Authority on request.

Related documents

Topics

Version history

2026-07-07

source file (current)