Code
Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes)
Status not confirmedView on BMA's website Source document
Summary
This is a tracked-changes draft of the BMA's Operational Resilience and Outsourcing Code, which sets out requirements for how licensed entities must build resilience into important business services and manage third-party outsourcing arrangements. It replaces the Authority's 2019 Outsourcing Guidance Notes and is issued under the licensing provisions of several sectoral Acts, meaning non-compliance can be treated as a failure to meet minimum licensing criteria.
- Scope: Applies to banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers, digital asset businesses (Class F), commercial insurers (Classes 3A, 3B, 4, C, D, E), IIGB and IILT insurers, and insurance managers, brokers, marketplace providers and agents; sandbox/test licensees are excluded.
- Board governance: Boards (or delegated committees) must oversee operational resilience and outsourcing, receive regular management information, and annually review and approve important business services, impact tolerances, disruption scenarios, the outsourcing risk management policy, testing outcomes, and the self-assessment.
- Op Res lifecycle: Entities must identify important business services, map supporting resources, set impact tolerances, prepare communication plans, test against severe but plausible disruption scenarios, remediate gaps, and conduct lessons-learned reviews.
- Outsourcing management: Requires governance and oversight of outsourcing, risk assessment (including sub-outsourcing/chain outsourcing), transparency and accountability of third-party providers, BMA access for inspection, client/data safeguarding, and contingency arrangements.
- Self-assessment and returns: Entities must produce and retain an annual self-assessment (methodology, business services, impact tolerances, scenarios, testing outcomes, remediation actions) and submit it or a BMA-specified scenario assessment when required, retaining records for at least five years.
The Code sets phased implementation deadlines, with most relevant entities required to comply by 31 March 2028, while banks and deposit companies licensed under the BDCA face an earlier deadline (the text shows tracked-change markup indicating a change from 31 March 2026 to 1 January 2027, so the exact final date should be confirmed against the clean version of the Code).
Key obligations
- Boards or delegated responsible parties must review and approve, at least annually, the list of important business services and their impact tolerances
- Boards or delegated responsible parties must review Business Continuity Plans and Disaster Recovery Plans, including those tied to outsourcing, and their testing results
- Boards or delegated responsible parties must review and approve identified severe but plausible disruption scenarios at least annually
- Boards or delegated responsible parties must review and approve a risk management policy for outsourcing at least annually
- Boards or delegated responsible parties must review operational resilience testing outcomes at least annually and approve remediation plans or investments
- Boards or delegated responsible parties must approve all material outsourcing arrangements and regularly review reports on outsourcing arrangements
- Relevant entities must make an annual self-assessment available to the BMA demonstrating adherence to the Code, containing methodology, business services list, impact tolerance rationale, scenarios, testing outcomes and remediation measures
- For important business services outside impact tolerance, the self-assessment must describe planned corrective actions and timelines
- Entities forming part of a group must include intra-group services in the self-assessment
- Boards must review and approve the self-assessment prior to submission, after senior management or a delegated party has reviewed it
- Relevant entities must retain self-assessment and filing/return documentation for a minimum of five years and make it available to the BMA on request
- Relevant entities must adhere to the Code's requirements by the applicable implementation deadline (31 March 2028 generally, or an earlier date for BDCA-licensed entities)
Applies to
Corporate Service Providers, Trust Businesses, Money Service Businesses, Investment Businesses, Fund Administration Provider Businesses, Banks and Deposit Companies, Digital Asset Businesses (Class F), Commercial Insurers (Classes 3A, 3B, 4, C, D, E), IIGB and IILT Insurers, Insurance Managers, Insurance Brokers, Insurance Marketplace Providers and Agents
Deadlines
- 31 March 2028: General implementation deadline by which relevant entities must adhere to the Code's requirements.
- 31 March 2026 / 1 January 2027 (tracked-changes text ambiguous): Earlier implementation deadline specifically for entities licensed under the Banks and Deposit Companies Act; the source text shows overlapping tracked-change dates, so the final effective date should be verified against a clean copy of the Code.
- annually: Recurring obligation for the Board or delegated responsible party to review and approve important business services, impact tolerances, disruption scenarios, the outsourcing risk policy, testing outcomes and the self-assessment.
- minimum of five years: Retention period for self-assessment and other filing/return documentation, to be made available to the BMA upon request.
Related documents
- This document is made under Banks and Deposit Companies Act 1999
- This document is made under Fund Administration Provider Business Act 2019
- This document is made under Insurance Act 1978
- This document is made under Investment Business Act 2003
- This document is made under Digital Asset Business Act 2018
- This document is made under Trusts (Regulation of Trust Business) Act 2001