Consultation Paper
Stakeholder Letter: CSP Code of Practice and Statement of Principles Consultation Response (2019-12-16)
IssuedView on BMA's website Source document
Summary
This is a stakeholder letter from the Bermuda Monetary Authority responding to industry feedback on its consultation to revise the Code of Practice and Statement of Principles under the Corporate Service Provider Business Act 2012. It does not introduce new rules itself but clarifies how the Authority interprets and will supervise several existing Code requirements for licensed Corporate Service Providers (CSPs).
- Timely execution: The Authority will use reasonable judgement in assessing whether a licensed CSP handles matters within its control, such as obtaining consents and approvals for clients, in an effective and timely manner.
- Client due diligence: No fixed minimum threshold applies to verifying a client's source of funds; CSPs must take a risk-based approach in line with the Proceeds of Crime (AML/ATF) Regulations 2008, the 2016 AML/ATF Guidance Notes and the Annex VI sector-specific guidance for CSPs, and must reasonably understand client corporate structures.
- Adequate personnel: The Authority's testing of compliance is an internal process and will be assessed proportionately based on a CSP's nature, scale and complexity; significant concerns may be raised on-site or as a formal issue requiring licensee action.
- Complaint procedures: Mere acknowledgement of a complaint is not sufficient; CSPs are expected to address client concerns in a manner reasonable and appropriate to the nature of the complaint, following investigation.
- Cooperation with regulatory authorities: CSPs must use reasonable judgement to notify the Authority of significant developments in staffing (e.g. business strategy shifts or major staff volume changes) and of new technology services with outsourcing implications, which may require pre-approval under the June 2019 Outsourcing Guidance Note.
The letter is explanatory in nature, aimed at clarifying the Authority's supervisory expectations following the consultation, rather than setting a new commencement date or transition period for the revised Code and Statement of Principles.
Key obligations
- Licensed CSPs must verify client source of funds using a risk-based approach consistent with the Proceeds of Crime (AML/ATF) Regulations 2008 and related AML/ATF Guidance Notes.
- Licensed CSPs must reasonably understand their clients' corporate vehicles and structures.
- Licensed CSPs must address client complaints substantively and appropriately, not merely acknowledge receipt of them.
- Licensed CSPs must notify the Authority of significant developments in staffing using reasonable judgement.
- Licensed CSPs must notify the Authority of new technology services that have outsourcing implications and may need to seek pre-approval under the June 2019 Outsourcing Guidance Note.
Applies to
Corporate Service Providers (CSPs), licensed CSPs