Consultation Paper
NOTICE: Corporate Service Provider Business Act 2012 – Code of Practice and Statement of Principles (revised) (2019-09-26)
DraftView on BMA's website Source document
Summary
This is a Bermuda Monetary Authority (BMA) consultation notice releasing a revised draft Code of Practice and revised draft Statement of Principles under the Corporate Service Provider Business Act 2012. It applies to corporate service providers (CSPs) licensed under section 11 of the Act, and sets out the standards, procedures and principles the Authority expects licensed CSPs to observe, as well as how the Authority will assess prudent conduct and exercise its supervisory powers.
Proposed Code of Practice changes
- Client money: CSPs holding client monies would need to verify the source of those monies and segregate client funds from their own, with clear recordkeeping to identify client funds at all times.
- Client due diligence and acceptance: Additional requirements for client acceptance procedures and documented policies on new client engagements.
- Conflicts of interest: Expectation that all reasonable steps are taken to manage conflicts and that conflict of interest procedures are documented.
- Governance: No use of corporate directors on a licensed CSP's board; the full board is expected to be responsible for the compliance function and for mitigating undue influence risk where shareholder controllers also sit as directors.
- Physical presence: New guidance on how a CSP can demonstrate adequate physical presence in Bermuda.
- Cybersecurity and records: Material cybersecurity incidents must be logged and reported promptly to the Authority; recordkeeping systems must protect records from loss, theft, unauthorised access or destruction.
- Staffing: Staff must receive supervision appropriate to their role, with up to date training and development logs, and enhanced recruitment practices at hiring and on an ongoing basis.
- Complaints and advertising: Complaints must be documented in writing under a transparent process; new requirements govern the form and content of advertisements, and licensed status must be displayed on a CSP's website if one is maintained.
Proposed Statement of Principles changes
- Enforcement references: References to the superseded 2012 Statement of Principles on enforcement are replaced with references to the 2018 Enforcement Guide.
- Source of wealth: Shareholder controllers of CSPs would be expected to demonstrate their source of wealth to the business and to the Authority, both on acquisition of shares and ongoing.
- Insurance: Professional indemnity insurance would be required at a minimum to satisfy the licensing criterion on adequate insurance, with guidance on how adequacy of cover is assessed.
As a consultation document, these revisions are not yet in force; stakeholders were invited to submit comments to the Authority before the changes are finalised and adopted.
Key obligations
- Stakeholders wishing to comment on the proposed revised Code of Practice and Statement of Principles must submit comments to policy@bma.bm on or before 28 October 2019.
- Once adopted, licensed corporate service providers holding client monies would need to verify the source of those funds and segregate client money from their own funds with clear identifying records.
- Once adopted, licensed corporate service providers would need to log and promptly report material cybersecurity incidents to the Authority.
- Once adopted, licensed corporate service providers would need to submit a certificate of compliance, signed by an officer, certifying compliance with the minimum licensing criteria.
Applies to
corporate service providers, limited corporate service provider licence holders
Deadlines
- 28 October 2019: Deadline for stakeholders to submit consultation comments on the revised Code of Practice and Statement of Principles to policy@bma.bm.