Consultation Paper
CP - Amendment to the Group Supervision Rules (May 2021)
DraftView on BMA's website Source document
Summary
This is a BMA consultation paper proposing amendments to the Insurance (Group Supervision) Rules 2011, to align them with the new Insurance Sector Operational Cyber Risk Management Code of Conduct. It sets out new definitions, governance clarifications, and a new cyber risk management and reporting regime for insurance groups where the BMA acts as group supervisor. The paper includes a draft of the Insurance (Group Supervision) Amendment Rules 2021 and invites stakeholder comments by 12 June 2021.
- New definitions: Adds defined terms for information asset, information security, Chief Information Security Officer (CISO), cyber risk programme, and cyber reporting event.
- Governance changes: Requires senior executives and the parent board to have access to the person responsible for information security (CISO), and makes the parent board explicitly accountable for the group's cyber risk posture, strategic direction and oversight of information security.
- Risk management framework: Expands the operational risk component of the risk management framework to cover risks to information assets, including those managed by related and third parties.
- New cyber risk programme obligation: Requires every insurance group to implement a cyber risk programme, evidenced by policies and documentation proportionate to the nature, scale and complexity of its business.
- New cyber event reporting obligation: Requires notification to the BMA within 72 hours of determination or confirmation of a significant cyber reporting event, followed by a written report within 14 days, with a fuller root cause report to follow if not initially complete.
- Reporting flexibility: Allows a designated insurer to satisfy BMA reporting by furnishing a copy of a similar report already filed with a local regulator, or by notifying the BMA that such a report was filed, with the BMA obtaining details via supervisory college exchange.
The draft amendment rules attached to the paper are stated to come into operation on 1 July 2022, though this consultation paper itself is a draft proposal seeking industry feedback before finalisation. The BMA notes it does not intend to oversee cyber risk of insurance groups for which it is not the group supervisor.
Key obligations
- Every insurance group must implement a cyber risk programme to ensure the information security of its information assets, evidenced by policies and documentation proportionate to the nature, scale and complexity of its business.
- The parent board must provide overall strategic direction, adequate oversight and challenge to the group's information security, and must approve a cyber risk policy document at least annually.
- Senior executives and the parent board must have access to the person responsible for information security (CISO).
- Every insurance group must notify the BMA within 72 hours of determination or confirmation of a cyber reporting event with significant adverse impact on the group's operations, policyholders or clients.
- The insurance group must furnish the BMA with a written report setting out known pertinent particulars within 14 days of the notification, even if root cause is unconfirmed.
- If the initial report is incomplete due to complexity, a full report with root cause analysis must be submitted promptly once concluded.
- Where a similar local reporting requirement exists, the designated insurer must furnish the BMA a copy of the local written report, or notify the BMA that such a report was filed locally.
- The risk management framework's operational risk component must address risks to information assets, including those managed by related and third parties.
- Stakeholders wishing to comment on the proposals must send comments to policy@bma.bm by 12 June 2021.
Applies to
insurance groups, designated insurers, registrants supervised on a group basis by the BMA
Deadlines
- 12 June 2021: Deadline for stakeholders to submit comments on the consultation proposals to policy@bma.bm.
- within 72 hours: Insurance group must notify the BMA after determination or confirmation of a reportable cyber event, whichever is sooner.
- within 14 days of notification: Insurance group must furnish the BMA with a written report setting out known pertinent particulars of the cyber event.
- at least annually: Board of directors and senior management must approve a cyber risk policy document.
- July 1, 2022: Stated commencement date of the draft Insurance (Group Supervision) Amendment Rules 2021 attached to the consultation paper.
Related documents
- This document amends Insurance (Group Supervision) Rules 2011