Consultation Paper

NOTICE: Trusts (Regulation of Trust Business) Act 2001 – Code of Practice and Statement of Principles (revised) (2019-09-26)

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Current version last checked: 2026-07-07

Summary

This is a BMA consultation notice posting a revised Code of Practice and a revised Statement of Principles (SoP) issued under the Trusts (Regulation of Trust Business) Act 2001. Both documents apply to holders of trust business licences (licensed undertakings) under the Act and set out the standards, procedures and principles the Authority expects them to observe, plus the criteria the Authority uses in supervising them. The notice describes the substantive proposed changes to each document; it is a draft open for industry comment, not yet a final binding version.

Proposed Code of Practice changes

  • Conflicts of interest: Licensed undertakings would need to take all reasonable steps to manage conflicts and document conflict of interest procedures.
  • Trust creation review: Understanding of the rationale for structures must be documented and reviewed for ongoing suitability, not just at inception.
  • Client money segregation: Client funds must be segregated from the undertaking's own funds, with documented recordkeeping enabling client funds to be clearly identified at all times (client money defined).
  • Corporate directors barred: The Authority confirmed it will not permit corporate directors on the board of a licensed trust business.
  • Board compliance oversight: The entire board is expected to be responsible for the compliance function and aware of its role in maintaining a robust compliance framework.
  • Physical presence and undue influence: Expectations were added on demonstrating adequate physical presence in Bermuda and mitigating undue board influence where shareholder controllers also sit as directors.
  • Recordkeeping and cybersecurity: Policies must ensure records are accurate, accessible and protected from loss, theft or unauthorised access; material cybersecurity incidents must be logged and promptly reported to the Authority.
  • Staff supervision, training and recruitment: Staff must receive supervision appropriate to their role, training and development logs must be kept up to date, and recruitment practices must be enhanced for all employees.
  • Complaints handling: Complaint details must be documented in writing and the complaints procedure must be transparent.
  • Advertising and website disclosure: New requirements govern the form and content of advertisements, and licensed status must be displayed on the licensee's website if one is maintained.
  • Notification of significant developments: The list of significant developments that licensed undertakings must proactively bring to the Authority's attention was expanded.

Proposed Statement of Principles changes

  • Enforcement references updated: References to the superseded 2012 Statement of Principles on enforcement were replaced with the 2018 Enforcement Guide; former Parts 4 and 5 were deleted as duplicative.
  • Corporate governance criteria: The SoP was updated to interpret paragraph 1A (Corporate Governance) of the First Schedule to the Act, reflecting 2014 changes to minimum licensing criteria.
  • Shareholder controller source of wealth: Shareholder controllers must be able to demonstrate their source of wealth to the business and the Authority both on acquisition of shares and on an ongoing basis; the undertaking must notify the Authority immediately of material concerns about a controller's suitability.
  • Prudent conduct factors: Additional non-exhaustive factors the Authority considers when assessing whether an undertaking is prudently run were added.
  • Insurance and liquidity: The prescribed list of required insurance types was removed but professional indemnity insurance remains a minimum requirement; new provisions expand liquidity requirements and define qualifying liquid assets.
  • Ethical conduct and staff competence: Expectations were added that business be conducted ethically, honestly and by appropriately skilled and knowledgeable staff.

Because this is a consultation draft, none of the proposed provisions are yet in force; stakeholders were invited to submit comments to the Authority using the attached comment form by the stated deadline before any final revised Code or SoP is issued.

Key obligations

  • Licensed undertakings must have documented policies and procedures to manage or avoid conflicts of interest and keep adequate records of conflicts as they arise
  • Licensed undertakings must document the rationale for trust structures at creation and review suitability on an ongoing basis, not only at inception
  • Licensed undertakings holding client money must segregate client funds from their own funds and maintain recordkeeping practices that clearly identify client funds at all times
  • Licensed trust businesses may not have corporate directors on their board
  • Licensed undertakings must log material cybersecurity incidents and report them promptly to the Authority
  • Licensed undertakings must maintain up-to-date staff training and development logs and provide supervision appropriate to staff roles
  • Licensed undertakings must document complaint details in writing and operate a transparent complaints handling procedure
  • Licensed undertakings must display their licensed status on their website if they maintain one
  • Licensed undertakings must proactively notify the Authority of significant developments as specified in the Code
  • Shareholder controllers must be able to demonstrate their source of wealth to the undertaking and the Authority both on acquisition of shares and on an ongoing basis
  • Licensed undertakings must notify the Authority immediately upon becoming aware of material concerns regarding the suitability of a shareholder controller
  • Licensed undertakings must maintain professional indemnity insurance at a minimum
  • Stakeholders wishing to comment on the draft Code and SoP must submit comments to the Authority by the stated consultation deadline

Applies to

trust businesses licensed under the Trusts (Regulation of Trust Business) Act 2001, licensed undertakings, limited trust business licence holders

Deadlines

  • 28 October 2019: Deadline for stakeholders to submit consultation comments on the revised Code of Practice and Statement of Principles to the Authority

Topics

Version history

2026-07-07

source file (current)

2026-07-07

source file