Consultation Paper
CP - Digital Asset Issuance Rules 2020
DraftView on BMA's website Source document
Summary
This is a consultation draft of the Digital Asset Issuance Rules 2020, published by the Bermuda Monetary Authority (BMA) under the Digital Asset Issuance Act 2020. It sets out detailed proposed rules for entities issuing digital assets to the public in or from Bermuda, covering the content of issuance documents, ongoing disclosure duties, IT and cybersecurity standards, custody of assets, AML/ATF compliance measures, and exemptions. As a consultation draft it is not yet in force, but it signals the detailed compliance regime the BMA intends to impose on digital asset issuers once finalised.
- Issuance document content: Issuers must include extensive minimum information in the issuance document, including issuer and group details, project description, technology and cybersecurity infrastructure, financial projections, offer terms, fees, risks, custodial arrangements, soft/hard caps, and cooling-off/refund procedures.
- Ongoing disclosures: Issuers must update acquirers on milestone progress, notify material changes before they take effect (or as soon as practicable if unforeseeable), and disclose removal or replacement of service providers.
- Periodic reporting: Issuers must file periodic electronic returns with the Authority containing organisational, financial, transactional and client data, accompanied by a signed director/officer declaration of accuracy.
- Risk management and market abuse controls: Issuers must maintain a risk management and internal controls framework and implement systems to prevent, detect and report insider market abuse where digital assets trade on secondary markets.
- IT and cybersecurity: Issuers must maintain technology and cybersecurity infrastructure meeting international best practice, operate a data audit node in Bermuda, and file cyber security reports and maintain a cyber security program.
- Custody of assets: Rules prescribe requirements for custody of digital asset acquirer assets, including use of qualified custodians where a third party holds assets.
- AML/ATF compliance measures: Issuers must apply appropriate customer due diligence and identity verification measures, cease transactions where required, apply enhanced due diligence, appoint a Reporting Officer and Compliance Officer, manage reliance on third parties, keep records (including for at least five years for suspicious transaction investigations), and undergo internal compliance audits.
- Exemptions: Issuers relying on exemptions under section 16(2) of the Act must file an exemption form with the Authority before proceeding; reduced rule sets apply to issuers using an accredited digital asset business, local issuers, and issuances already authorised by another competent authority.
Because this text is a consultation draft, the obligations described are proposed requirements that would take effect only once the Rules are finalised and made; readers should check the BMA's consultation outcome and final published Rules before treating these as binding.
Key obligations
- Issuers must include all specified minimum information (issuer details, project description, technology, risks, fees, offer terms, custody arrangements, caps, cooling-off/refund procedures) in the issuance document
- Issuers must provide acquirers with periodic updates on milestone progress at the frequency disclosed in the issuance document
- Issuers must inform acquirers of material changes before they take effect, or as soon as practicable if unforeseeable
- Issuers must inform acquirers of removal or replacement of any service provider named in the issuance document as soon as practicable
- Issuers must file periodic electronic returns with the Authority within the period and intervals specified in their authorization, accompanied by a signed accuracy declaration from two directors or a director and officer
- Issuers must implement internal arrangements to prevent, detect and report insider market abuse where assets trade on secondary markets
- Issuers must maintain a risk management and internal controls framework complying with Authority guidelines for the duration of authorization and beyond as specified
- Issuers must maintain technological and cybersecurity infrastructure meeting international best practice and file cyber security reports
- Issuers must establish and maintain a data audit node in Bermuda for the duration of authorization plus five years after the offering ends
- Issuers must apply customer due diligence, verification of identity, enhanced due diligence, and cease transactions where required under AML/ATF compliance measures
- Issuers must appoint a Reporting Officer and a Compliance Officer
- Issuers must keep records, including investigation-related records, for a minimum of five years and make them available to the Authority and law enforcement
- Issuers must carry out an internal compliance review/audit of the digital asset issuance and submit findings with a certificate of compliance
- Issuers relying on an exemption under section 16(2) of the Act must file an exemption form with the Authority before proceeding with the issuance
- Local issuers are exempt from appointing a local representative and from certain other rules
Applies to
digital asset issuers, local issuers, accredited digital asset businesses, AML/ATF regulated financial institutions, service providers to digital asset issuers, third party custodians
Deadlines
- within five business days: A person relied on for due diligence must, if requested, make available information about the digital asset acquirer within five business days of the request
- five years: Records of investigations into complex, unusually large, or unusual patterns of transactions must be kept for a minimum of five years
- period specified in its authorization: Issuers must file periodic returns with the Authority within the period and at intervals specified in their authorization
- duration of authorization plus five years after offering ends: Issuers must maintain a data audit node in Bermuda for the duration of authorization and for five years following the end of the offering