Consultation Paper

Consultation Paper - Cyber Risk Management Code of Conduct

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Current version last checked: 2026-07-07

Summary

This is a Bermuda Monetary Authority consultation paper seeking comment on a proposed Operational Cyber Risk Management Code of Conduct. The draft Code, attached as an appendix, would set minimum cybersecurity governance, risk management and incident reporting expectations for a range of BMA-licensed sectors. It is not yet in force; the Authority is inviting feedback before finalising it.

  • Scope: Applies to banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers licensed by the BMA.
  • Governance: Draft Code would require board and senior management oversight of cyber risk, annual board approval of a cyber risk policy, and appointment of a Chief Information Security Officer.
  • Risk management programme: Would require an operational cyber risk management programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls.
  • Outsourcing and cloud: Would require risk assessment and oversight of outsourced and cloud-based cyber functions, read together with the Outsourcing Guidance Notes 2019.
  • Incident reporting: Would require notification of cyber reporting events to the Authority and documented incident management processes.
  • Business continuity: Would require Business Continuity and Disaster Recovery plans, tested at least annually, with documentation of issues and remediation.
  • Record retention: Would require risk assessments to be documented and retained for at least five years and made available to the Authority on request.

The paper asks stakeholders to submit comments on the proposals to policy@bma.bm by 10 December 2021. The draft Code itself states it would come into force on a date in 2022 that is left as a placeholder ('YY 2022') in this consultation draft, so the actual effective and compliance dates were not yet fixed at the time of publication.

Key obligations

  • Submit any comments on the consultation proposals to policy@bma.bm no later than 10 December 2021.
  • Under the draft Code, once finalised, relevant licensed entities (RLEs) would need to have their board approve a cyber risk policy at least annually and maintain ongoing board/senior management oversight of cyber risk.
  • Under the draft Code, RLEs would need to implement an operational cyber risk management programme including risk assessment, data governance/classification controls, and detection, protection, response and recovery controls.
  • Under the draft Code, RLEs would need to appoint a suitably qualified Chief Information Security Officer (internal or outsourced).
  • Under the draft Code, RLEs would need to risk-assess outsourced and cloud computing arrangements and maintain oversight and contractual terms covering compliance, cooperation with the Authority, and data access.
  • Under the draft Code, RLEs would need to notify the Authority of cyber reporting events.
  • Under the draft Code, RLEs would need to retain risk assessment documentation for at least five years and produce it to the Authority on request.
  • Under the draft Code, RLEs would need to maintain and test Business Continuity and Disaster Recovery plans at least annually, documenting and tracking remediation of any issues identified.

Applies to

banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses, fund administration providers

Deadlines

  • 10 December 2021: Deadline for stakeholders to submit comments on the consultation paper to policy@bma.bm.
  • 1 YY 2022 (placeholder date in draft): Draft Code states it comes into force on this date, with RLEs required to comply by 'YY 2022' - exact date not finalised in this consultation draft.

Topics

Version history

2026-07-07

source file (current)