Consultation Paper
Digital Asset Custody Code of Practice 2018
DraftView on BMA's website Source document
Summary
This is a 2018 consultation draft from the Bermuda Monetary Authority setting out proposed custody standards for digital asset businesses (DABs) that hold or are responsible for clients' private keys. It was issued for industry comment alongside eight specific consultation questions and is not yet in force as final guidance. If adopted, it would sit under the Digital Asset Business Act 2018 and the existing Digital Asset Business Code of Practice, elaborating on how custodians must safeguard client digital assets.
- Business controls: Proposed requirements cover hot/cold storage thresholds and liquidity, one time use addresses, fraud detection, proof of asset valuation, personnel screening and dedicated roles, annual IT security training, outsourcing and supply chain oversight, insurability, service level agreements, customer due diligence, disclosure and reporting standards, proof of reserves, and operational risk management including incident reporting and business continuity planning.
- Custody safekeeping: Draft standards would govern seed and key generation, data sanitisation, secure storage and backup of seeds/keys, physical security of storage facilities, key compromise and revocation procedures, handling of personnel departures, account segregation, location redundancy, and mandatory reporting of security breaches.
- Transaction handling: Proposed rules address multi-signature authorisation, collusion mitigation, evidence based signature approvals, periodic transaction audits, and recorded evidence/audit data backups.
- Operations controls: Draft provisions would require multi-factor authentication, baseline IT security controls, logical access management, security testing, secure development lifecycle practices, recurring digital asset testing, disaster recovery planning, external audit, and scrutiny/justification of automation.
- Interpretation approach: The Code frames 'must'/'shall' as mandatory (or an equivalent standard the DAB can demonstrate), 'should' as a strong recommendation departures from which must be documented, and 'may' as optional; DABs would be expected to document risk assessments and retain them for at least five years.
As a consultation paper, the document invited industry feedback on eight numbered questions (e.g. on the proposed 90 percent cold storage threshold, valuation methodology, HSM security levels, and multi-signature key thresholds), with comments due to the Authority by 18 January 2019. Because it remains a draft, none of the described standards are confirmed as final binding rules pending the Authority's review of consultation responses.
Key obligations
- Proposed requirement that DABs document custody risk assessments and retain them for at least five years, available to the Authority on request
- Proposed threshold that at least 90 percent of digital assets be held in cold storage at all times, unless a documented exception applies
- Proposed requirement for mandatory annual IT security awareness training for all staff
- Proposed requirement for mandatory reporting of security breaches to the Authority
- Proposed requirement for multi-signature (M-of-N) authorisation on outbound transactions
- Proposed requirement for periodic audits of transactions and of backup seeds
- Proposed requirement to maintain an operational risk management programme including incident reporting and business continuity/alternate site plans
- Proposed requirement for external audit of custody operations
- Submission of consultation comments to the Authority (innovate@bma.bm) by the stated deadline
Applies to
Digital Asset Business (DAB) licensees responsible for custody of client private keys, digital asset custodians
Deadlines
- 18 January 2019: Deadline for industry and interested persons to submit comments on the consultation paper and its eight questions to innovate@bma.bm