Code

Trusts (Regulation of Trust Business) Act 2001 - Code of Practice (December 2019)

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This Code of Practice is issued by the Bermuda Monetary Authority under section 7 of the Trusts (Regulation of Trust Business) Act 2001. It sets out the duties, standards and sound principles expected of all holders of trust business licences, applied proportionately according to each licensee's nature, scale and complexity. While non-compliance is not itself an offence, the Authority takes adherence to the Code into account when assessing whether a licensee is conducting business prudently, and persistent breaches are likely to lead to formal action.

  • Client due diligence and AML/CFT: Licensees must have risk-based CDD procedures, know the identity of settlors, protectors, custodians and (to the fullest extent possible) beneficiaries on an ongoing basis, and verify the source of assets introduced, in line with Bermuda's proceeds of crime and anti-terrorism financing legislation.
  • Integrity, ethics and conflicts of interest: Undertakings must act with integrity, treat beneficiaries' interests as paramount, and maintain documented policies to manage or avoid conflicts of interest, keeping records where conflicts arise.
  • Trust creation and delegation: Licensees must satisfy themselves that a trust is established for a lawful purpose, fully understand the trust deed, ensure trust property is properly brought under their control, and retain full records where trust business is delegated to them.
  • Client money and segregation of funds: Trust funds must be kept separate from the licensee's own funds and from other trusts' funds absent proper consents, with accurate records reconciled at least monthly and client money policies reviewed at least annually.
  • Board practices and governance: Corporate trustees must have boards comprised solely of individuals (no corporate directors), with the board responsible for oversight of compliance and risk management.
  • Fees, complaints and advertising: Licensees must agree clear, transparent fee structures in advance, give adequate notice of fee changes, maintain a transparent and timely complaints process with written records, and ensure advertising is clear, ethical and does not breach the Act or other laws.
  • Risk management framework: Licensees must implement a risk management framework commensurate with their business's scale and risk profile, with board oversight aligned to risk appetite and tolerance.
  • Disclosure and cooperation with regulators: Licensees should disclose their licensed status on websites, advertisements and correspondence, and must proactively alert the Authority to material business developments such as staffing changes, cybersecurity incidents, criminal proceedings, amalgamations, sale of the business, or issues affecting continued compliance with licensing criteria.

The Code applies generally to all trust business licence holders in Bermuda and may be revised from time to time, with the Authority required to publish and consult on draft material changes before adoption.

Key obligations

  • Licensees must carry out risk-based client due diligence before acting for any new client and comply with applicable proceeds of crime and anti-terrorism financing legislation
  • Licensees must know the identity of each settlor, protector and custodian on an ongoing basis and, to the fullest extent possible, the beneficiaries, and verify the source of assets introduced
  • Licensees must maintain documented policies to manage or avoid conflicts of interest and keep records of conflicts that arise
  • Licensees must keep trust funds separate from their own funds and from other trusts' funds unless proper consents or trust instrument provisions permit pooling, with full ownership records maintained
  • Licensees must maintain up to date, accurate client money records reconciled at least monthly
  • Licensees must review client money policies, systems and controls at least annually
  • Corporate trust licensees must ensure their board of directors is comprised solely of individuals, not corporate directors
  • Licensees must agree a clear fee structure with each relevant person in advance and give adequate notice of material fee changes
  • Licensees must maintain a written record of complaints, including response and action taken
  • Licensees must implement a risk management framework commensurate with the scale and risk profile of their business
  • Licensees should disclose their licensed status on their website (if maintained) and in advertisements and correspondence
  • Licensees should proactively alert the Authority to material business developments including staffing, systems and controls changes, material insurance claims, criminal proceedings, amalgamations or acquisitions, sale of the trust business, material cybersecurity incidents, or issues affecting ability to meet licensing criteria

Applies to

holders of trust business licences, licensed undertakings under the Trusts (Regulation of Trust Business) Act 2001, holders of limited trust business licences, undertakings also holding a corporate service provider business licence

Deadlines

  • at least monthly: Client money records must be reconciled at least monthly or more frequently per internal controls
  • at least annually: Client money policies, systems and controls must be reviewed at least annually

Related documents

Topics

Version history

2026-07-07

source file (current)