Code
Operational Resilience and Outsourcing Code (September 2025)
Status not confirmedView on BMA's website Source document
Summary
This Code, issued by the Bermuda Monetary Authority under multiple sectoral Acts, sets out mandatory operational resilience and outsourcing requirements for regulated entities. It requires firms to identify their important client-facing business services, map the resources supporting them, set impact tolerances, prepare communication plans, and test resilience against severe but plausible disruption scenarios, embedding this into board-level governance.
- Scope: Applies to banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses (standard licence), fund administration provider businesses, digital asset businesses (Class F), and various insurance entities (commercial insurers, IIGB/IILT insurers, insurance managers, brokers, marketplace providers and agents); entities under a regulatory sandbox or test licence are excluded.
- Governance: The Board is ultimately responsible for operational resilience and outsourcing; it or a delegated party must approve Op Res governance, review important business services and impact tolerances annually, approve material outsourcing arrangements, and approve the outsourcing risk management policy annually.
- Op Res lifecycle: Firms must identify important business services, map supporting resources (people, processes, technology, facilities, information), set impact tolerances, develop internal/external communication plans, test against severe but plausible disruption scenarios, remediate gaps, and conduct lessons-learned exercises.
- Outsourcing controls: Firms must establish governance and oversight standards for outsourcing, assess and monitor outsourcing risks (including sub-contracting/chain outsourcing), ensure transparency and accountability of service providers, safeguard client data, and maintain contingency arrangements.
- Self-assessment: Entities must prepare an annual self-assessment (methodology, important business services and impact tolerances, disruption scenarios considered, testing outcomes, remediation plans) for the BMA, reviewed by senior management and approved by the Board, and retained for at least five years.
- Notification: Entities must notify the BMA of significant developments impacting delivery of important business services.
The Code supersedes the BMA's 2019 Outsourcing Guidance Notes and should be read alongside the accompanying Operational Resilience and Outsourcing Guidance Notes. Compliance is required by 31 March 2028 generally, except for entities licensed under the Banks and Deposit Companies Act, which must comply by 1 January 2027.
Key obligations
- Boards must approve Op Res governance and programmes and review the list of important business services and impact tolerances at least annually
- Boards or delegated parties must review and approve identified severe but plausible disruption scenarios at least annually
- Boards or delegated parties must review and approve the outsourcing risk management policy at least annually
- Boards or delegated parties must approve all material outsourcing arrangements and regularly review outsourcing reports
- Entities must identify important business services and map the resources (people, processes, technology, facilities, information) supporting them
- Entities must set impact tolerances for each important business service and develop internal and external communication plans for disruptions
- Entities must test resilience against severe but plausible disruption scenarios and conduct remediation and lessons-learned exercises when results fall outside tolerance
- Entities must prepare an annual self-assessment demonstrating adherence to the Code, reviewed by senior management and approved by the board, and make it available to the BMA
- Entities must retain self-assessments for a minimum of five years and provide them to the BMA upon request
- Entities must notify the BMA of significant developments impacting the delivery of important business services when they occur
- Entities must comply with the Code's requirements by 31 March 2028, or by 1 January 2027 if licensed under the Banks and Deposit Companies Act
Applies to
Corporate Service Providers, Trust Businesses, Money Service Businesses, Investment Businesses, Fund Administration Provider Businesses, Banks and Deposit Companies, Digital Asset Businesses (Class F), Commercial Insurers (Class 3A, 3B, 4, C, D, E), IIGB and IILT Insurers, Insurance Managers, Insurance Brokers, Insurance Marketplace Providers and Agents
Deadlines
- 31 March 2028: General deadline for Relevant Entities to adhere to the Code's requirements
- 1 January 2027: Deadline for entities licensed under the Banks and Deposit Companies Act to adhere to the Code's requirements
- annually: Board or delegated responsible party must review and approve the list of important business services, impact tolerances, disruption scenarios, outsourcing risk management policy, and self-assessment
- minimum of five years from date of completion: Retention period for self-assessments, to be made available to the BMA upon request
Related documents
- This document is made under Banks and Deposit Companies Act 1999
- This document is made under Fund Administration Provider Business Act 2019
- This document is made under Insurance Act 1978
- This document is made under Investment Business Act 2003
- This document is made under Digital Asset Business Act 2018
- This document is made under Trusts (Regulation of Trust Business) Act 2001