Consultation Paper

Consultation Paper - DAB Operational Cyber Risk Code

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Current version last checked: 2026-07-07

Summary

This is a Bermuda Monetary Authority consultation notice inviting comment on a draft new Digital Asset Business Operational Cyber Risk Management Code of Practice, together with related revisions to the DAB Custody Code of Practice, the DAB Code of Practice, and new Digital Asset Business (Cyber Risk) Rules 2022. The package is intended to align DAB cyber requirements with those already applied to Bermuda's insurance, banking, trust, corporate services and investments sectors, while imposing more stringent controls in areas of heightened DAB-specific risk such as audit trails, systems testing, incident reporting, smart contracts and blockchain security.

  • Scope: Applies to all Digital Asset Business (DAB) registrants/licensees under the Digital Asset Business Act 2018, including Class F, Class M and Class T licence holders.
  • Draft Code content: Proposes mandatory board-level cyber risk governance, appointment of a Chief Information Security Officer, an operational cyber risk management programme, documented risk assessments retained for at least five years, an annual IT audit plan, incident notification to the Authority, and specific controls for outsourcing, cloud computing, smart contracts and DLT/blockchain security.
  • Draft Cyber Risk Rules: Would require Class F licence holders to file an annual cyber risk return and Class M/T licence holders to file on the date specified in their licence, each accompanied by a declaration signed by the CISO and a senior executive or director.
  • Consultation mechanics: Comments on the draft documents are to be submitted via the Authority's online survey link, with the deadline extended from 6 May 2022 to 6 June 2022.

As a consultation paper, none of the proposed Code or Rules provisions are yet in force; they represent draft requirements that DABs and other interested parties are invited to review and comment on before finalisation.

Key obligations

  • Submit comments on the draft Consultation Documents to the Authority via the specified survey link no later than 6 June 2022
  • Under the draft Code, DABs would need to implement an operational cyber risk management programme with board-approved annual cyber risk policy and CISO oversight
  • Under the draft Code, DABs would need to document and retain risk assessments for at least five years and produce them to the Authority on request
  • Under the draft Code, DABs would need to develop and have the audit committee approve an annual IT audit plan
  • Under the draft Cyber Risk Rules, Class F licence holders would need to file an annual cyber risk return, and Class M and Class T licence holders would need to file on the date specified in their licence, each declared accurate by the CISO and a senior executive or director

Applies to

Digital Asset Business (DAB) registrants, Class F licence holders, Class M licence holders, Class T licence holders

Deadlines

  • 6 June 2022: Extended deadline for submitting comments on the draft DAB Operational Cyber Risk Management Code of Practice and related Consultation Documents (extended from 6 May 2022)

Topics

Version history

2026-07-07

source file (current)